{
 "use_case": "security-questionnaire",
 "title": "Security questionnaire: four buyer questions against an approved answer library",
 "about": "Four rows of a fictional buyer's security questionnaire (CSV), answered from a fictional vendor's approved answer library and policies. The policy and encryption questions must fill from approved answers, the out-of-date pen-test answer must not pass as approved, the bug-bounty question (nothing approved) must be left for a person, and the signed review record must verify and catch a forged status.",
 "licence": "Fictional: Tallyloom, Corvid Freight and Pellham & Vose LLP are invented. The questionnaire is written for Decosa in the shape of the CSA CAIQ (domain, question id, question); it is not CAIQ text. Part of decosa-api, AGPL-3.0-or-later.",
 "inputs": [
  {
   "file": "inputs/questionnaire.csv",
   "what": "The buyer's questionnaire: a CSV or XLSX with a column headed Question (ID and Section optional), or one question per line."
  },
  {
   "file": "inputs/library.json",
   "what": "Your approved answer library: {company, entries: [{id, question, answer, yes_no, sources}], documents: [{id, title, kind, text}]}."
  }
 ],
 "steps": [
  {
   "id": "parse",
   "method": "POST",
   "path": "/questionnaire/parse",
   "body": {
    "questionnaire": {
     "file": {
      "name": "questionnaire.csv",
      "text": {
       "$file": "inputs/questionnaire.csv"
      }
     }
    }
   }
  },
  {
   "id": "answer",
   "method": "POST",
   "path": "/questionnaire/answer",
   "body": {
    "questionnaire": {
     "file": {
      "name": "questionnaire.csv",
      "text": {
       "$file": "inputs/questionnaire.csv"
      }
     }
    },
    "library": {
     "$file": "inputs/library.json"
    }
   }
  },
  {
   "id": "verify",
   "method": "POST",
   "path": "/questionnaire/verify",
   "auth": false,
   "body": {
    "record": {
     "$ref": "answer.record"
    },
    "answers": {
     "$ref": "answer.items"
    }
   }
  },
  {
   "id": "tampered",
   "method": "POST",
   "path": "/questionnaire/verify",
   "auth": false,
   "body": {
    "record": {
     "$ref": "answer.record"
    }
   },
   "tamper": {
    "at": "record.items[id=TVM-03].status",
    "set": "approved"
   }
  }
 ],
 "checks": [
  {
   "says": "the CSV questionnaire parses into four questions",
   "path": "parse.questions",
   "count": 4
  },
  {
   "says": "the security-policy question (GOV-01) fills from an approved answer",
   "path": "answer.items[id=GOV-01][0].status",
   "equals": "approved"
  },
  {
   "says": "the encryption question (CEK-01) fills from approved answers naming AES-256 and TLS 1.2",
   "path": "answer.items[id=CEK-01,status=approved][0].answer",
   "contains": [
    "AES-256",
    "TLS 1.2"
   ]
  },
  {
   "says": "the out-of-date pen-test answer (TVM-01) is not passed as approved",
   "path": "answer.items[id=TVM-01][0].status",
   "in": [
    "review",
    "policy",
    "none"
   ]
  },
  {
   "says": "the bug-bounty question (TVM-03) is left for a person",
   "path": "answer.items[id=TVM-03][0].status",
   "equals": "none"
  },
  {
   "says": "no question errored",
   "path": "answer.counts.error",
   "equals": 0
  },
  {
   "says": "the signed review record verifies",
   "path": "verify.valid_signature",
   "equals": true
  },
  {
   "says": "the answers match the hashes in the record",
   "path": "verify.answers_match",
   "equals": true
  },
  {
   "says": "a record with the bug-bounty row forged to approved no longer verifies",
   "path": "tampered.valid_signature",
   "equals": false
  },
  {
   "says": "every model call has a signed receipt",
   "receipts": "signed",
   "min": 4
  }
 ]
}
