{
 "use_case": "cmmc-evidence-map",
 "title": "CMMC evidence map: a machine shop's SSP says everything is implemented; the evidence says otherwise",
 "about": "A fictional 38-person machine shop preparing for a CMMC Level 2 self-assessment. The SSP claims every requirement is implemented except 3.13.11 (planned). Planted: a lockout setting that never locks (3.1.8), a year-old audit log export (3.3.1), MFA shown only in a screenshot where the all-users policy is report-only (3.5.3), a draft password standard (3.5.7), a visitor log with no escort column (3.10.3, which can never go on a POA&M), encryption planned (3.13.11) and an anti-malware export from a system outside the scope (3.14.2). 3.1.1 and 3.11.2 are fully evidenced, 3.1.1 with a verified Decosa test run. The run must never call a planted gap fully evidenced, flag the stale, draft and out-of-scope artefacts, verify the test run, mark 3.10.3 as never on a POA&M, show no score, and sign a record that verifies and fails when changed. (The hosted service's refusals of unmarked and CUI-marked sets are covered by the smoke test and the unit tests, since a self-hosted box in real-data mode accepts both.)",
 "licence": "Synthetic: the company, people, systems and evidence are invented (decosa_api/verticals/cmmc/synth.py and pool.py); the screenshot is drawn by scripts/cmmc_make_sample_png.py; the test-run certificate is a real Decosa run against saucedemo.com, Sauce Labs' public test site. NIST SP 800-171 and 800-171A are US government works. Part of decosa-api, AGPL-3.0-or-later.",
 "inputs": [
  {
   "file": "inputs/system.json",
   "what": "The system in scope: name, organisation, assessment date and the in-scope asset names."
  },
  {
   "file": "inputs/ssp.json",
   "what": "The SSP statements: requirement, status, text and the artefacts each cites."
  },
  {
   "file": "inputs/artefacts.json",
   "what": "Ten artefacts (policy, config exports, logs, records, a scan, a screenshot as a data URL, a test-run certificate)."
  }
 ],
 "steps": [
  {
   "id": "map",
   "method": "POST",
   "path": "/cmmc/map",
   "body": {
    "system": {
     "$file": "inputs/system.json"
    },
    "ssp": {
     "$file": "inputs/ssp.json"
    },
    "artefacts": {
     "$file": "inputs/artefacts.json"
    },
    "requirements": [
     "3.1.1",
     "3.1.8",
     "3.3.1",
     "3.5.3",
     "3.5.7",
     "3.10.3",
     "3.11.2",
     "3.13.11",
     "3.14.2"
    ],
    "synthetic": true
   },
   "timeout": 600
  },
  {
   "id": "verify",
   "method": "POST",
   "path": "/record/verify",
   "auth": false,
   "body": {
    "$ref": "map.record"
   }
  },
  {
   "id": "tampered",
   "method": "POST",
   "path": "/record/verify",
   "auth": false,
   "body": {
    "$ref": "map.record"
   },
   "tamper": {
    "at": "statement.status",
    "set": "no_gaps_in_evidence"
   }
  }
 ],
 "checks": [
  {
   "says": "encryption is only planned in the SSP, so 3.13.11 has no evidence",
   "path": "map.requirements[id=3.13.11][0].status",
   "equals": "missing"
  },
  {
   "says": "3.1.8 has a planted gap, so it is not fully evidenced",
   "path": "map.requirements[id=3.1.8][0].status",
   "not_equals": "present"
  },
  {
   "says": "3.3.1 has a planted gap, so it is not fully evidenced",
   "path": "map.requirements[id=3.3.1][0].status",
   "not_equals": "present"
  },
  {
   "says": "3.5.3 has a planted gap, so it is not fully evidenced",
   "path": "map.requirements[id=3.5.3][0].status",
   "not_equals": "present"
  },
  {
   "says": "3.5.7 has a planted gap, so it is not fully evidenced",
   "path": "map.requirements[id=3.5.7][0].status",
   "not_equals": "present"
  },
  {
   "says": "3.10.3 has a planted gap, so it is not fully evidenced",
   "path": "map.requirements[id=3.10.3][0].status",
   "not_equals": "present"
  },
  {
   "says": "3.13.11 has a planted gap, so it is not fully evidenced",
   "path": "map.requirements[id=3.13.11][0].status",
   "not_equals": "present"
  },
  {
   "says": "3.14.2 has a planted gap, so it is not fully evidenced",
   "path": "map.requirements[id=3.14.2][0].status",
   "not_equals": "present"
  },
  {
   "says": "3.10.3 (escort visitors) can never go on a POA&M",
   "path": "map.poam.rows[requirement=3.10.3][0].poam_eligible",
   "equals": false
  },
  {
   "says": "3.13.11 may go on a POA&M only when encryption is employed but not FIPS-validated",
   "path": "map.poam.rows[requirement=3.13.11][0].poam_eligible",
   "equals": "conditional"
  },
  {
   "says": "the two-year-old audit log export is flagged stale",
   "path": "map.evidence_index[id=A4][0].issues[0].code",
   "equals": "stale"
  },
  {
   "says": "the password standard is flagged as a draft",
   "path": "map.evidence_index[id=A5][0].issues[0].code",
   "equals": "draft"
  },
  {
   "says": "the anti-malware export from a system outside the scope is flagged",
   "path": "map.evidence_index[id=A9][0].issues[0].code",
   "equals": "out_of_scope"
  },
  {
   "says": "the Decosa test-run certificate verifies",
   "path": "map.evidence_index[id=T1][0].certificate.ok",
   "equals": true
  },
  {
   "says": "the screenshot was read by the vision model",
   "path": "map.evidence_index[id=S1][0].transcribed",
   "equals": true
  },
  {
   "says": "some objectives have evidence present",
   "path": "map.counts.objectives.present",
   "min": 8
  },
  {
   "says": "no score or estimate is shown for 9 of 110 requirements",
   "path": "map.estimate.shown",
   "equals": false
  },
  {
   "says": "the gap map lists the draft POA&M",
   "path": "map.gap_map_md",
   "contains": "## Draft POA&M"
  },
  {
   "says": "the signed record verifies",
   "path": "verify.ok",
   "equals": true
  },
  {
   "says": "a record with its status changed no longer verifies",
   "path": "tampered.ok",
   "equals": false
  },
  {
   "says": "every model call has a signed receipt",
   "receipts": "signed",
   "min": 20
  }
 ]
}
