{
  "ok": true,
  "scope": "MaxArc Global Health Impact Platform — Cybersecurity, Threat, Vulnerability, Security Testing, and Response Governance (synthetic demonstration)",
  "notice": "All records are synthetic, masked, and non-identifiable. This is a simulation only and not a live or production security system. It performs no scanning, exploitation, live monitoring, log ingestion, or autonomous response.",
  "authorizedReviewOnlyLabel": "FOR GLOBAL FUND / CCM / AUTHORIZED PARTNER REVIEW ONLY",
  "permittedUse": "For authorized Global Fund / CCM / partner governance review of synthetic cybersecurity governance only.",
  "summary": {
    "totalAssets": 20,
    "criticalAssets": 10,
    "exposedAssets": 0,
    "assetsMissingThreatModel": 1,
    "threatModels": 12,
    "threatModelsPendingReview": 9,
    "threatScenarios": 30,
    "threatScenarioHypotheses": 30,
    "attackSurfaces": 10,
    "openSecurityRisks": 10,
    "criticalHighRisks": 6,
    "totalFindings": 22,
    "unreviewedVulnerabilities": 2,
    "verifiedVulnerabilities": 4,
    "falsePositives": 2,
    "duplicateFindings": 2,
    "reopenedFindings": 1,
    "blockedFindings": 1,
    "remediatedPendingValidation": 1,
    "overdueRemediation": 2,
    "ineffectiveRemediation": 3,
    "pendingEffectivenessReviews": 6,
    "activeRiskAcceptances": 2,
    "expiringRiskAcceptances": 3,
    "expiredRiskAcceptances": 0,
    "activeExceptions": 5,
    "expiredExceptions": 2,
    "failedTests": 4,
    "partialTests": 4,
    "blockedTests": 4,
    "notTestedTests": 3,
    "unknownDependencyProvenance": 3,
    "supplyChainRisks": 6,
    "highRiskDependencies": 3,
    "privilegeReviewConcerns": 8,
    "configurationReviewGaps": 4,
    "interfaceExposureConcerns": 8,
    "controlAssessmentGaps": 5,
    "securityEvents": 12,
    "declaredIncidents": 7,
    "incidentsAwaitingContainment": 1,
    "incidentsAwaitingRecovery": 10,
    "closurePendingIncidents": 1,
    "reopenedIncidents": 1,
    "disclosureReviewsPending": 3,
    "notificationDecisionsBlocked": 3,
    "secondReviewQueue": 26,
    "separationOfDutiesConflicts": 35,
    "separationOfDutiesRules": 35,
    "missingEvidence": 2,
    "conflictingEvidence": 3,
    "staleEvidence": 6,
    "aiSignalCount": 20,
    "auditEvents": 23,
    "byModule": {
      "fund-accountability": 2,
      "stockpile-logistics": 2,
      "lab-operations": 2,
      "patient-continuity": 1,
      "restricted-patient-locator": 1,
      "asset-management": 1,
      "program-performance": 1,
      "ai-intelligence": 1,
      "country-rollout": 1,
      "authorized-review-room": 1,
      "executive-review-packet": 1,
      "identity-access-governance": 1,
      "data-quality-reconciliation": 1,
      "risk-incident-case-governance": 1,
      "policy-compliance-control-governance": 1,
      "service-reliability-continuity": 1,
      "interoperability-data-exchange-governance": 1
    },
    "byAssetCategory": {
      "application": 4,
      "api-interface": 4,
      "data-store-governance-label": 4,
      "batch-process": 4,
      "dashboard": 4
    },
    "byDomain": {
      "governance": 1,
      "identity-and-access": 1,
      "authentication": 1,
      "authorization": 1,
      "privileged-access": 1,
      "application-security": 1,
      "api-and-interface-security": 1,
      "data-protection": 1,
      "privacy": 1,
      "encryption-governance": 1,
      "key-management-governance-label": 1,
      "secrets-management-governance-label": 1,
      "infrastructure-security": 1,
      "network-security": 1
    },
    "byThreatCategory": {
      "unauthorized-access": 1,
      "excessive-privilege": 1,
      "session-misuse": 1,
      "credential-compromise": 1,
      "insider-misuse": 1,
      "data-exposure": 1,
      "data-alteration": 1,
      "record-deletion-attempt": 1,
      "audit-suppression-attempt": 1,
      "duplicate-or-replay-activity": 1,
      "interface-spoofing": 1,
      "message-tampering": 1,
      "stale-authorization": 1,
      "consent-status-misuse": 1,
      "restricted-locator-misuse": 1,
      "commodity-diversion-concealment": 1,
      "laboratory-result-alteration": 1,
      "program-result-manipulation": 1,
      "asset-custody-manipulation": 1,
      "evidence-package-substitution": 1,
      "download-authorization-bypass": 1,
      "dependency-compromise": 1,
      "supply-chain-compromise": 1,
      "misconfiguration": 1,
      "availability-disruption": 1,
      "synchronization-abuse": 1,
      "ai-prompt-or-output-misuse": 1,
      "ai-generated-false-evidence": 1,
      "privilege-escalation": 1,
      "insecure-exception-use": 1
    },
    "byVulnerabilitySeverity": {
      "low": 6,
      "medium": 6,
      "high": 5,
      "critical": 5
    },
    "byFindingState": {
      "unreviewed": 2,
      "pending-verification": 2,
      "verified": 2,
      "false-positive": 2,
      "duplicate": 2,
      "remediation-planned": 2,
      "remediation-in-progress": 2,
      "remediated-pending-validation": 1,
      "validated-closed": 1,
      "risk-accepted": 1,
      "exception-active": 1,
      "expired-exception": 1,
      "reopened": 1,
      "blocked-insufficient-evidence": 1,
      "not-applicable": 1
    },
    "byTestResult": {
      "pass": 4,
      "partial": 4,
      "fail": 4,
      "blocked": 4,
      "not-tested": 3,
      "not-applicable": 3
    },
    "byIncidentState": {
      "event-only": 1,
      "triage-pending": 1,
      "investigation-pending": 1,
      "incident-declared": 1,
      "contained": 1,
      "eradication-pending": 1,
      "recovery-pending": 1,
      "monitoring": 1,
      "closure-pending": 1,
      "closed-after-approval": 1,
      "reopened": 1,
      "blocked-insufficient-evidence": 1,
      "disproven": 1
    },
    "byRiskAcceptanceStatus": {
      "approved": 4,
      "pending": 1,
      "rejected": 1
    },
    "byExceptionStatus": {
      "approved": 5,
      "expired": 2,
      "rejected": 2,
      "withdrawn": 2,
      "pending": 1
    },
    "byRemediationStatus": {
      "planned": 2,
      "in-progress": 2,
      "completed": 4,
      "overdue": 2,
      "reopened": 2
    },
    "boundaryReminder": {
      "impactDomain": "impact.maxarchealth.com",
      "impactPort": "3201",
      "medicalLibraryBoundary": "library.maxarchealth.com remains separate (port 3101, not used here)",
      "maxTraxEhrBoundary": "MaxTrax EHR remains separate; this is not a full EHR"
    }
  },
  "positioning": {
    "isSyntheticGovernanceDemonstration": true,
    "isSimulationOnly": true,
    "isNotLiveSiem": true,
    "isNotSecurityOperationsCenter": true,
    "isNotIntrusionDetectionSystem": true,
    "isNotIntrusionPreventionSystem": true,
    "isNotEndpointDetectionPlatform": true,
    "isNotVulnerabilityScanner": true,
    "isNotPenetrationTestingTool": true,
    "isNotExploitFramework": true,
    "isNotMalwareAnalysisEnvironment": true,
    "isNotThreatIntelligenceFeed": true,
    "isNotLiveLogCollector": true,
    "isNotNetworkMonitoringSystem": true,
    "isNotFirewallManagementSystem": true,
    "isNotSecretsManagementSystem": true,
    "isNotAutomatedIncidentResponsePlatform": true,
    "isNotProductionSecurityEnforcementEngine": true,
    "isNotReplacementForAuthorizedSecurityTeams": true,
    "noNetworkScanning": true,
    "noPortScanning": true,
    "noVulnerabilityExploitation": true,
    "noExploitPayloads": true,
    "noMalwareExecution": true,
    "noCredentialTesting": true,
    "noPasswordCracking": true,
    "noBruteForceTesting": true,
    "noPhishingOrSocialEngineering": true,
    "noSecretOrTokenExtraction": true,
    "noLogIngestion": true,
    "noPacketCapture": true,
    "noExternalSecurityCalls": true,
    "noCveFeedIngestion": true,
    "noCloudSecurityIntegration": true,
    "noRealAlerts": true,
    "noRealNotifications": true,
    "noRealTicketCreation": true,
    "noRealFileUpload": true,
    "noRealEvidenceDownload": true,
    "noRealDatabaseWrites": true,
    "noAutomatedContainment": true,
    "noAccountDisabling": true,
    "noPrivilegeRevocation": true,
    "noFirewallChanges": true,
    "noServiceRestart": true,
    "noAutonomousIncidentDeclaration": true,
    "noAutonomousVulnerabilityClosure": true,
    "noAutonomousRiskAcceptance": true,
    "sourceModuleRecordsAuthoritative": true,
    "notAnEhr": true,
    "coversModules": [
      "fund-accountability",
      "stockpile-logistics",
      "lab-operations",
      "patient-continuity",
      "restricted-patient-locator",
      "asset-management",
      "program-performance",
      "ai-intelligence",
      "country-rollout",
      "authorized-review-room",
      "executive-review-packet",
      "identity-access-governance",
      "data-quality-reconciliation",
      "risk-incident-case-governance",
      "policy-compliance-control-governance",
      "service-reliability-continuity",
      "interoperability-data-exchange-governance"
    ]
  },
  "cybersecurityPosture": {
    "statement": "A threat scenario is not proof that an attack occurred; a risk score is not proof of compromise; threat-model completeness does not prove security. Source-module records remain authoritative and security decisions require authorized human review.",
    "threatScenarioIsNotProofOfAttack": true,
    "riskScoreIsNotProofOfCompromise": true,
    "threatModelCompletenessDoesNotProveSecurity": true,
    "missingThreatsRemainVisible": true,
    "lowConfidenceHypothesesRemainVisible": true,
    "sourceModuleRecordsAuthoritative": true,
    "securityDecisionsRequireHumanReview": true,
    "aiHypothesesCannotBecomeFindingsWithoutReview": true
  },
  "threatModelPosture": {
    "statement": "Threat models are synthetic; missing threats and low-confidence hypotheses remain visible; AI-generated threat hypotheses cannot become findings without authorized human review.",
    "synthetic": true,
    "missingThreatsRemainVisible": true,
    "lowConfidenceHypothesesRemainVisible": true,
    "aiHypothesesRequireReview": true,
    "scenarioIsNotProof": true
  },
  "vulnerabilityPosture": {
    "statement": "Scanner-like detection is synthetic only. A finding is not automatically a confirmed vulnerability; severity is not proof of exploitability; exploitability labels are not exploit instructions.",
    "scannerLikeDetectionSyntheticOnly": true,
    "findingIsNotAutomaticallyConfirmed": true,
    "severityIsNotProofOfExploitability": true,
    "exploitabilityLabelsAreNotExploitInstructions": true,
    "falsePositivesRemainVisible": true,
    "duplicatesRemainLinkedAndVisible": true,
    "missingEvidenceBlocksVerified": true,
    "remediationCompletionDoesNotProveEffectiveness": true,
    "closureRequiresValidation": true,
    "laterClosureDoesNotEraseHistory": true,
    "reopenedFindingsRemainVisible": true,
    "acceptedRiskIsNotRemediation": true,
    "exceptionIsNotPermanentAcceptance": true,
    "expiredExceptionsCannotRemainActive": true
  },
  "testingPosture": {
    "statement": "A passed review does not prove the absence of vulnerabilities; testing does not authorize production deployment. No exploit payloads, attack commands, active scanning, credential attempts, destructive tests, or production probing are included.",
    "passedReviewDoesNotProveAbsenceOfVulnerabilities": true,
    "testingDoesNotAuthorizeProductionDeployment": true,
    "missingEvidenceBlocksPass": true,
    "partialRemainsPartial": true,
    "blockedRemainsVisible": true,
    "notTestedDistinctFromNotApplicable": true,
    "failedTestsRemainVisibleAfterRetest": true,
    "retestsAppendHistory": true,
    "testerCannotIndependentlyApproveHighRiskConclusions": true,
    "noExploitPayloadsOrAttackCommands": true,
    "noActiveScanningOrCredentialAttempts": true,
    "noDestructiveOrProductionProbing": true
  },
  "dependencyPosture": {
    "statement": "No external package registry is queried and no live CVE feed is used. Version age is not proof of vulnerability; a known advisory reference is synthetic; dependency presence does not prove compromise.",
    "noExternalRegistryQueried": true,
    "noLiveCveFeedUsed": true,
    "versionAgeIsNotProofOfVulnerability": true,
    "advisoryReferencesAreSynthetic": true,
    "dependencyPresenceDoesNotProveCompromise": true,
    "supplyChainSuspicionIsNotFindingWithoutEvidence": true,
    "unknownProvenanceRemainsVisible": true,
    "highRiskDependenciesRequireHumanReview": true,
    "removalOrUpgradeNotPerformedHere": true
  },
  "configurationReviewPosture": {
    "statement": "Configuration records are synthetic; no actual server configuration is read. No Apache, PM2, systemd, firewall, DNS, TLS, operating-system, or network configuration is changed.",
    "configurationRecordsAreSynthetic": true,
    "noActualServerConfigurationRead": true,
    "noInfrastructureConfigurationChanged": true,
    "secureLabelDoesNotProveSecureImplementation": true,
    "unknownConfigurationRemainsUnknown": true,
    "missingEvidencePreventsFinalApproval": true
  },
  "eventIncidentPosture": {
    "statement": "An event is not automatically an incident; an alert is not proof of attack; an anomaly is not proof of compromise. Incident declaration requires a human decision.",
    "eventIsNotAutomaticallyIncident": true,
    "alertIsNotProofOfAttack": true,
    "anomalyIsNotProofOfCompromise": true,
    "incidentDeclarationRequiresHumanDecision": true,
    "dataExposureUnknownWhenEvidenceInsufficient": true,
    "containmentDoesNotProveEradication": true,
    "eradicationDoesNotProveRecovery": true,
    "recoveryDoesNotEraseIncidentHistory": true,
    "closureRequiresCriteriaAndApproval": true,
    "postIncidentReviewDistinctFromRecovery": true,
    "externalNotificationRequiresSeparateAuthorizedReview": true,
    "noRealNotificationOccurs": true
  },
  "containmentRecoveryPosture": {
    "statement": "Recommendations do not execute actions. This module cannot disable accounts, revoke privileges, rotate credentials, change infrastructure, suspend production interfaces, restart services, or notify external parties. Execution remains with authorized operational teams.",
    "recommendationsDoNotExecuteActions": true,
    "cannotDisableAccounts": true,
    "cannotRevokePrivileges": true,
    "cannotRotateCredentials": true,
    "cannotChangeInfrastructure": true,
    "cannotSuspendProductionInterfaces": true,
    "cannotRestartServices": true,
    "cannotNotifyExternalParties": true,
    "executionRemainsWithAuthorizedOperationalTeams": true
  },
  "riskAcceptancePosture": {
    "statement": "Risk acceptance is not remediation. Acceptance must be attributable, time-bound, and revocable; expired acceptance must not remain active; the risk owner cannot independently approve their own acceptance; AI cannot approve or recommend automatic acceptance.",
    "riskAcceptanceIsNotRemediation": true,
    "mustBeAttributable": true,
    "mustBeTimeBound": true,
    "mustBeRevocable": true,
    "expiredAcceptanceNotActive": true,
    "missingApprovalBlocksActive": true,
    "highAndCriticalRequireIndependentOrSecondReview": true,
    "ownerCannotApproveOwnAcceptance": true,
    "aiCannotApproveOrRecommendAutomaticAcceptance": true
  },
  "exceptionPosture": {
    "statement": "Exceptions are attributable, justified, scoped, time-bound, approved, revocable, monitored, and audited. Expired, rejected, withdrawn, or unapproved exceptions are not active.",
    "attributable": true,
    "justified": true,
    "scoped": true,
    "timeBound": true,
    "approved": true,
    "revocable": true,
    "monitored": true,
    "audited": true,
    "expiredRejectedWithdrawnUnapprovedNotActive": true
  },
  "remediationPosture": {
    "statement": "Completion is not effectiveness. Overdue and ineffective remediation remain visible; the action owner cannot independently validate high-risk effectiveness; remediation does not erase original findings or incidents; ineffective remediation may reopen a finding or incident.",
    "completionIsNotEffectiveness": true,
    "overdueActionsRemainVisible": true,
    "ineffectiveRemediationRemainsVisible": true,
    "ownerCannotValidateHighRiskEffectiveness": true,
    "remediationDoesNotEraseOriginalFindings": true,
    "unresolvedResidualRiskRemainsVisible": true,
    "ineffectiveRemediationMayReopen": true
  },
  "disclosurePosture": {
    "statement": "No real notification occurs; notification review is not notification. Incident declaration does not automatically require external disclosure; disclosure decisions require authorized human review; legal and regulatory determinations are outside this module.",
    "noRealNotificationOccurs": true,
    "notificationReviewIsNotNotification": true,
    "declarationDoesNotAutomaticallyRequireDisclosure": true,
    "disclosureDecisionsRequireHumanReview": true,
    "legalRegulatoryDeterminationsOutsideModule": true,
    "insufficientEvidenceMayBlockFinalDecision": true,
    "restrictedDetailsRemainMinimumNecessary": true,
    "denialsDoNotRevealRestrictedRecordExistence": true
  },
  "separationOfDutiesPosture": {
    "statement": "Separation-of-duties violations remain blocked or pending, identify the violated rule, require reassignment/independent/second review, remain auditable, and are never silently overridden.",
    "violationsRemainBlockedOrPending": true,
    "violationsIdentifyRule": true,
    "violationsRequireReassignmentIndependentOrSecondReview": true,
    "violationsAuditable": true,
    "neverSilentlyOverridden": true
  },
  "auditPosture": {
    "statement": "Audit events are synthetic, immutable, and append-only. Deletion is not an allowed governance control. Source-module records remain authoritative and this is not a production cryptographic audit ledger.",
    "appendOnly": true,
    "immutable": true,
    "deletionNotAllowed": true,
    "sourceModuleRecordsAuthoritative": true,
    "notProductionCryptographicLedger": true,
    "historicalFailuresIncidentsExceptionsAcceptedRisksRemainVisible": true,
    "requiredLinkedEventTypes": [
      "threat-model-version-change",
      "risk-reassessment",
      "vulnerability-verification",
      "false-positive-decision",
      "duplicate-linkage",
      "remediation-status-change",
      "remediation-validation",
      "finding-closure",
      "finding-reopen",
      "risk-acceptance-approval",
      "risk-acceptance-expiration-or-revocation",
      "exception-approval",
      "exception-expiration-or-revocation",
      "security-test-execution",
      "security-retest",
      "incident-declaration",
      "containment-decision",
      "eradication-decision",
      "recovery-decision",
      "notification-review-decision",
      "incident-closure",
      "incident-reopen",
      "disclosure-review-decision"
    ]
  },
  "aiPosture": {
    "statement": "AI is assistive only. It may prioritize, summarize, and flag for authorized human reviewers, but never scans, exploits, declares incidents, verifies vulnerabilities, approves severity/closure, accepts risk, approves exceptions, disables accounts, revokes privileges, rotates credentials, suspends interfaces, changes configuration, restarts services, suppresses findings, fabricates evidence, notifies external parties, authorizes disclosure, or bypasses human review, evidence, expiration, revocation, separation of duties, or audit controls.",
    "assists": [
      "identify missing threat models",
      "identify stale security reviews",
      "suggest threat scenarios",
      "detect control gaps",
      "identify duplicate vulnerability findings",
      "flag missing evidence",
      "prioritize vulnerabilities by synthetic risk",
      "identify overdue remediation",
      "compare remediation with validation evidence",
      "identify privilege concentration",
      "identify unusual access-governance patterns",
      "identify dependency concentration",
      "flag unknown provenance",
      "identify possible interface exposure",
      "summarize incident chronology",
      "identify inconsistent incident states",
      "recommend independent or second review",
      "detect expired acceptances or exceptions",
      "identify potentially ineffective remediation",
      "reconcile security findings with source-module evidence"
    ],
    "mustNot": [
      "scan networks",
      "scan ports",
      "exploit vulnerabilities",
      "generate exploit payloads",
      "execute malware",
      "test credentials",
      "obtain or expose secrets",
      "call external security systems",
      "ingest live threat feeds",
      "declare incidents",
      "verify vulnerabilities autonomously",
      "approve severity",
      "approve closure",
      "accept risk",
      "approve exceptions",
      "disable accounts",
      "revoke privileges",
      "rotate credentials",
      "suspend interfaces",
      "change configuration",
      "alter infrastructure",
      "restart services",
      "suppress findings",
      "fabricate evidence",
      "notify external parties",
      "authorize disclosure",
      "bypass human review, evidence, expiration, revocation, separation of duties, or audit controls"
    ]
  },
  "humanControls": {
    "securityDecisionsRequireHumanReview": true,
    "incidentDeclarationRequiresHumanDecision": true,
    "vulnerabilityVerificationRequiresHumanReview": true,
    "closureRequiresHumanApproval": true,
    "riskAcceptanceRequiresAuthorizedApproval": true,
    "exceptionApprovalRequiresHumanReview": true,
    "disclosureRequiresAuthorizedHumanReview": true,
    "highRiskRequiresSecondReview": true
  },
  "boundary": {
    "impactDomain": "impact.maxarchealth.com",
    "impactPort": "3201",
    "medicalLibraryBoundary": "library.maxarchealth.com remains separate (port 3101, not used here)",
    "maxTraxEhrBoundary": "MaxTrax EHR remains separate; this is not a full EHR and implements no live integration or real database mutation.",
    "noInfrastructureBoundary": "No Apache, PM2, systemd, firewall, DNS, TLS, SSH, operating-system users, secrets, credentials, environment files, production logs, production databases, production networks, or real security tools are read, called, or modified. No outbound network call, port/network scan, exploit, credential test, log ingestion, packet capture, or notification occurs."
  },
  "modules": [
    {
      "key": "fund-accountability",
      "label": "fund accountability",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "stockpile-logistics",
      "label": "stockpile logistics",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "lab-operations",
      "label": "lab operations",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "patient-continuity",
      "label": "patient continuity",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "restricted-patient-locator",
      "label": "restricted patient locator",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "asset-management",
      "label": "asset management",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "program-performance",
      "label": "program performance",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "ai-intelligence",
      "label": "ai intelligence",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "country-rollout",
      "label": "country rollout",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "authorized-review-room",
      "label": "authorized review room",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "executive-review-packet",
      "label": "executive review packet",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "identity-access-governance",
      "label": "identity access governance",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "data-quality-reconciliation",
      "label": "data quality reconciliation",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "risk-incident-case-governance",
      "label": "risk incident case governance",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "policy-compliance-control-governance",
      "label": "policy compliance control governance",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "service-reliability-continuity",
      "label": "service reliability continuity",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    },
    {
      "key": "interoperability-data-exchange-governance",
      "label": "interoperability data exchange governance",
      "securityCoverage": "synthetic-governance-example",
      "sourceRecordsAuthoritative": true
    }
  ],
  "securityDomains": [
    "governance",
    "identity-and-access",
    "authentication",
    "authorization",
    "privileged-access",
    "application-security",
    "api-and-interface-security",
    "data-protection",
    "privacy",
    "encryption-governance",
    "key-management-governance-label",
    "secrets-management-governance-label",
    "infrastructure-security",
    "network-security",
    "endpoint-security",
    "dependency-security",
    "software-supply-chain",
    "logging-and-monitoring-governance",
    "incident-response",
    "continuity-and-recovery",
    "third-party-security",
    "secure-development",
    "change-management",
    "vulnerability-management",
    "configuration-management",
    "physical-security-governance-label",
    "training-and-awareness-governance"
  ],
  "threatCategories": [
    "unauthorized-access",
    "excessive-privilege",
    "session-misuse",
    "credential-compromise",
    "insider-misuse",
    "data-exposure",
    "data-alteration",
    "record-deletion-attempt",
    "audit-suppression-attempt",
    "duplicate-or-replay-activity",
    "interface-spoofing",
    "message-tampering",
    "stale-authorization",
    "consent-status-misuse",
    "restricted-locator-misuse",
    "commodity-diversion-concealment",
    "laboratory-result-alteration",
    "program-result-manipulation",
    "asset-custody-manipulation",
    "evidence-package-substitution",
    "download-authorization-bypass",
    "dependency-compromise",
    "supply-chain-compromise",
    "misconfiguration",
    "availability-disruption",
    "synchronization-abuse",
    "ai-prompt-or-output-misuse",
    "ai-generated-false-evidence",
    "privilege-escalation",
    "insecure-exception-use"
  ],
  "vulnerabilityStates": [
    "unreviewed",
    "pending-verification",
    "verified",
    "false-positive",
    "duplicate",
    "remediation-planned",
    "remediation-in-progress",
    "remediated-pending-validation",
    "validated-closed",
    "risk-accepted",
    "exception-active",
    "expired-exception",
    "reopened",
    "blocked-insufficient-evidence",
    "not-applicable"
  ],
  "testResultStates": [
    "pass",
    "partial",
    "fail",
    "blocked",
    "not-tested",
    "not-applicable"
  ],
  "incidentStates": [
    "event-only",
    "triage-pending",
    "investigation-pending",
    "incident-declared",
    "contained",
    "eradication-pending",
    "recovery-pending",
    "monitoring",
    "closure-pending",
    "closed-after-approval",
    "reopened",
    "blocked-insufficient-evidence",
    "disproven"
  ],
  "routes": [
    "/cybersecurity-threat-vulnerability-governance/security-assets",
    "/cybersecurity-threat-vulnerability-governance/security-domains",
    "/cybersecurity-threat-vulnerability-governance/threat-models",
    "/cybersecurity-threat-vulnerability-governance/threat-scenarios",
    "/cybersecurity-threat-vulnerability-governance/attack-surfaces",
    "/cybersecurity-threat-vulnerability-governance/trust-boundaries",
    "/cybersecurity-threat-vulnerability-governance/security-risks",
    "/cybersecurity-threat-vulnerability-governance/vulnerabilities",
    "/cybersecurity-threat-vulnerability-governance/vulnerability-findings",
    "/cybersecurity-threat-vulnerability-governance/dependency-risks",
    "/cybersecurity-threat-vulnerability-governance/supply-chain-risks",
    "/cybersecurity-threat-vulnerability-governance/configuration-reviews",
    "/cybersecurity-threat-vulnerability-governance/access-risk-reviews",
    "/cybersecurity-threat-vulnerability-governance/privilege-reviews",
    "/cybersecurity-threat-vulnerability-governance/data-protection-reviews",
    "/cybersecurity-threat-vulnerability-governance/interface-exposure-reviews",
    "/cybersecurity-threat-vulnerability-governance/security-controls",
    "/cybersecurity-threat-vulnerability-governance/control-assessments",
    "/cybersecurity-threat-vulnerability-governance/security-tests",
    "/cybersecurity-threat-vulnerability-governance/test-results",
    "/cybersecurity-threat-vulnerability-governance/security-events",
    "/cybersecurity-threat-vulnerability-governance/security-incidents",
    "/cybersecurity-threat-vulnerability-governance/containment-actions",
    "/cybersecurity-threat-vulnerability-governance/eradication-actions",
    "/cybersecurity-threat-vulnerability-governance/recovery-actions",
    "/cybersecurity-threat-vulnerability-governance/post-incident-reviews",
    "/cybersecurity-threat-vulnerability-governance/remediation",
    "/cybersecurity-threat-vulnerability-governance/risk-acceptances",
    "/cybersecurity-threat-vulnerability-governance/exceptions",
    "/cybersecurity-threat-vulnerability-governance/disclosure-reviews",
    "/cybersecurity-threat-vulnerability-governance/notification-decisions",
    "/cybersecurity-threat-vulnerability-governance/approval-chains",
    "/cybersecurity-threat-vulnerability-governance/evidence",
    "/cybersecurity-threat-vulnerability-governance/risk-signals",
    "/cybersecurity-threat-vulnerability-governance/audit-events",
    "/cybersecurity-threat-vulnerability-governance/separation-of-duties",
    "/cybersecurity-threat-vulnerability-governance/summary"
  ]
}