Synthetic
MaxArc Global Health Impact Platform
Cybersecurity, Threat, Vulnerability, Security Testing & Response Governance
Cross-module cybersecurity, threat, vulnerability, security-testing, and response governance.
A synthetic governance demonstration and simulation only — not a live SIEM, not a security operations center, not an intrusion detection or prevention system, not an endpoint-detection platform, not a vulnerability scanner, not a penetration-testing tool, not an exploit framework, not a malware-analysis environment, not a threat-intelligence feed, not a live log collector, not a network-monitoring or firewall-management system, not a secrets-management system, not an automated incident-response platform, and not a production security-enforcement engine. No network or port scanning, vulnerability exploitation, exploit payloads, malware execution, credential testing, password cracking, brute force, phishing, secret/token extraction, log ingestion, packet capture, external security calls, CVE-feed ingestion, real alerts/notifications, real ticketing, real upload/download, real database writes, automated containment, account disabling, privilege revocation, firewall changes, or service restarts occur. A threat scenario is not proof of attack; a risk score is not proof of compromise; a finding is not automatically a confirmed vulnerability; severity is not exploitability; completion is not effectiveness. No live monitoring and no log ingestion occur, and no autonomous containment or response is performed. Source-module records remain authoritative. AI is assistive only and never scans, exploits, declares incidents, verifies vulnerabilities, accepts risk, or bypasses human controls.
Business / security
Synthetic exposure
Remain visible
Author ≠ approver
Hypotheses, not proof
Score ≠ compromise
Second review
Not confirmed
Human-reviewed
Remain visible
Linked & visible
History preserved
Closure ≠ done
Remain visible
Completion ≠ effectiveness
Time-bound
Not active
Revocable
Not active
Visible after retest
Remain partial
Remain visible
Stays unknown
Suspicion ≠ finding
Least privilege
No config changed
Synthetic
Event ≠ incident
Human declared
Distinct phase
Distinct phase
Criteria + approval
History preserved
Review ≠ notification
Insufficient evidence
High-risk
Blocked / pending
Blocks verified / pass
Remain visible
Human review required
Append-only
Security domains
Synthetic security-governance domains only. Key-management and secrets-management appear as governance labels only; no keys, secrets, or credentials are stored or managed.
Governed security assets (missing threat models remain visible)
Every asset identifies source module, environment, data classification, business and security criticality, owner, custodian, reviewer, exposure, authentication/authorization/logging/continuity requirements, dependency/threat-model/risk/control references, review dates, human-review status, and audit reference. No real hostnames, IPs, URLs, endpoints, credentials, or infrastructure paths appear.
| Asset | Name / environment | Criticality / exposure | Posture / audit |
|---|---|---|---|
| SA-001 fund-accountability · application |
Synthetic fund accountability service 1 synthetic-demo · public |
low medium exposure exposed-synthetic |
threat model TM-001 · review reviewed · audit AE-001 |
| SA-002 stockpile-logistics · api-interface |
Synthetic stockpile logistics service 2 synthetic-staging-label · internal |
medium high exposure internal-only |
threat model TM-002 · review pending · audit AE-002 |
| SA-003 lab-operations · data-store-governance-label |
Synthetic lab operations service 3 synthetic-review · restricted |
high critical exposure internal-only |
threat model TM-003 · review reviewed · audit AE-003 |
| SA-004 patient-continuity · batch-process |
Synthetic patient continuity service 4 synthetic-demo · highly-restricted |
critical low exposure internal-only |
threat model none — visible · review reviewed · audit AE-004 |
| SA-005 restricted-patient-locator · dashboard |
Synthetic restricted patient locator service 5 synthetic-staging-label · public |
low medium exposure exposed-synthetic |
threat model TM-005 · review pending · audit AE-005 |
| SA-006 asset-management · application |
Synthetic asset management service 6 synthetic-review · internal |
medium high exposure internal-only |
threat model TM-006 · review reviewed · audit AE-006 |
| SA-007 program-performance · api-interface |
Synthetic program performance service 7 synthetic-demo · restricted |
high critical exposure internal-only |
threat model TM-007 · review reviewed · audit AE-007 |
| SA-008 ai-intelligence · data-store-governance-label |
Synthetic ai intelligence service 8 synthetic-staging-label · highly-restricted |
critical low exposure internal-only |
threat model TM-008 · review pending · audit AE-008 |
| SA-009 country-rollout · batch-process |
Synthetic country rollout service 9 synthetic-review · public |
low medium exposure exposed-synthetic |
threat model TM-009 · review reviewed · audit AE-009 |
| SA-010 authorized-review-room · dashboard |
Synthetic authorized review room service 10 synthetic-demo · internal |
medium high exposure internal-only |
threat model TM-010 · review reviewed · audit AE-010 |
| SA-011 executive-review-packet · application |
Synthetic executive review packet service 11 synthetic-staging-label · restricted |
high critical exposure internal-only |
threat model none — visible · review pending · audit AE-011 |
| SA-012 identity-access-governance · api-interface |
Synthetic identity access governance service 12 synthetic-review · highly-restricted |
critical low exposure internal-only |
threat model TM-012 · review reviewed · audit AE-012 |
| SA-013 data-quality-reconciliation · data-store-governance-label |
Synthetic data quality reconciliation service 13 synthetic-demo · public |
low medium exposure exposed-synthetic |
threat model TM-001 · review reviewed · audit AE-013 |
| SA-014 risk-incident-case-governance · batch-process |
Synthetic risk incident case governance service 14 synthetic-staging-label · internal |
medium high exposure internal-only |
threat model TM-002 · review pending · audit AE-014 |
| SA-015 policy-compliance-control-governance · dashboard |
Synthetic policy compliance control governance service 15 synthetic-review · restricted |
high critical exposure internal-only |
threat model TM-003 · review reviewed · audit AE-015 |
| SA-016 service-reliability-continuity · application |
Synthetic service reliability continuity service 16 synthetic-demo · highly-restricted |
critical low exposure internal-only |
threat model TM-004 · review reviewed · audit AE-016 |
| SA-017 interoperability-data-exchange-governance · api-interface |
Synthetic interoperability data exchange governance service 17 synthetic-staging-label · public |
low medium exposure exposed-synthetic |
threat model TM-005 · review pending · audit AE-017 |
| SA-018 fund-accountability · data-store-governance-label |
Synthetic fund accountability service 18 synthetic-review · internal |
medium high exposure internal-only |
threat model none — visible · review reviewed · audit AE-018 |
| SA-019 stockpile-logistics · batch-process |
Synthetic stockpile logistics service 19 synthetic-demo · restricted |
high critical exposure internal-only |
threat model TM-007 · review reviewed · audit AE-019 |
| SA-020 lab-operations · dashboard |
Synthetic lab operations service 20 synthetic-staging-label · highly-restricted |
critical low exposure internal-only |
threat model TM-008 · review pending · audit AE-020 |
Threat models (author ≠ approver; completeness ≠ security)
- TM-001 — Synthetic threat model for fund accountability approved 2nd reviewfund-accountability · author fund-accountability-threat-author ≠ approver fund-accountability-security-reviewer · missing threats visible: yes · gaps 1 · audit AE-001
- TM-002 — Synthetic threat model for stockpile logistics pending-reviewstockpile-logistics · author stockpile-logistics-threat-author ≠ approver stockpile-logistics-security-reviewer · missing threats visible: yes · gaps 0 · audit AE-002
- TM-003 — Synthetic threat model for lab operations draftlab-operations · author lab-operations-threat-author ≠ approver lab-operations-security-reviewer · missing threats visible: yes · gaps 0 · audit AE-003
- TM-004 — Synthetic threat model for patient continuity second-review-required 2nd reviewpatient-continuity · author patient-continuity-threat-author ≠ approver patient-continuity-security-reviewer · missing threats visible: yes · gaps 1 · audit AE-004
- TM-005 — Synthetic threat model for restricted patient locator approvedrestricted-patient-locator · author restricted-patient-locator-threat-author ≠ approver restricted-patient-locator-security-reviewer · missing threats visible: yes · gaps 0 · audit AE-005
- TM-006 — Synthetic threat model for asset management pending-reviewasset-management · author asset-management-threat-author ≠ approver asset-management-security-reviewer · missing threats visible: yes · gaps 0 · audit AE-006
- TM-007 — Synthetic threat model for program performance draft 2nd reviewprogram-performance · author program-performance-threat-author ≠ approver program-performance-security-reviewer · missing threats visible: yes · gaps 1 · audit AE-007
- TM-008 — Synthetic threat model for ai intelligence second-review-requiredai-intelligence · author ai-intelligence-threat-author ≠ approver ai-intelligence-security-reviewer · missing threats visible: yes · gaps 0 · audit AE-008
- TM-009 — Synthetic threat model for country rollout approvedcountry-rollout · author country-rollout-threat-author ≠ approver country-rollout-security-reviewer · missing threats visible: yes · gaps 0 · audit AE-009
- TM-010 — Synthetic threat model for authorized review room pending-review 2nd reviewauthorized-review-room · author authorized-review-room-threat-author ≠ approver authorized-review-room-security-reviewer · missing threats visible: yes · gaps 1 · audit AE-010
- TM-011 — Synthetic threat model for executive review packet draftexecutive-review-packet · author executive-review-packet-threat-author ≠ approver executive-review-packet-security-reviewer · missing threats visible: yes · gaps 0 · audit AE-011
- TM-012 — Synthetic threat model for identity access governance second-review-requiredidentity-access-governance · author identity-access-governance-threat-author ≠ approver identity-access-governance-security-reviewer · missing threats visible: yes · gaps 0 · audit AE-012
Threat scenarios (hypotheses, not proof of attack)
- TS-001 — unauthorized-access pending AI-suggestedSynthetic hypothesis: unauthorized access affecting fund accountability (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-002 — excessive-privilege reviewedSynthetic hypothesis: excessive privilege affecting stockpile logistics (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-003 — session-misuse pendingSynthetic hypothesis: session misuse affecting lab operations (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-004 — credential-compromise pending AI-suggestedSynthetic hypothesis: credential compromise affecting patient continuity (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-005 — insider-misuse reviewedSynthetic hypothesis: insider misuse affecting restricted patient locator (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-006 — data-exposure pendingSynthetic hypothesis: data exposure affecting asset management (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-007 — data-alteration pending AI-suggestedSynthetic hypothesis: data alteration affecting program performance (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-008 — record-deletion-attempt reviewedSynthetic hypothesis: record deletion attempt affecting ai intelligence (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-009 — audit-suppression-attempt pendingSynthetic hypothesis: audit suppression attempt affecting country rollout (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-010 — duplicate-or-replay-activity pending AI-suggestedSynthetic hypothesis: duplicate or replay activity affecting authorized review room (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-011 — interface-spoofing reviewedSynthetic hypothesis: interface spoofing affecting executive review packet (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-012 — message-tampering pendingSynthetic hypothesis: message tampering affecting identity access governance (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-013 — stale-authorization pending AI-suggestedSynthetic hypothesis: stale authorization affecting data quality reconciliation (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-014 — consent-status-misuse reviewedSynthetic hypothesis: consent status misuse affecting risk incident case governance (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-015 — restricted-locator-misuse pendingSynthetic hypothesis: restricted locator misuse affecting policy compliance control governance (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-016 — commodity-diversion-concealment pending AI-suggestedSynthetic hypothesis: commodity diversion concealment affecting service reliability continuity (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-017 — laboratory-result-alteration reviewedSynthetic hypothesis: laboratory result alteration affecting interoperability data exchange governance (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-018 — program-result-manipulation pendingSynthetic hypothesis: program result manipulation affecting fund accountability (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-019 — asset-custody-manipulation pending AI-suggestedSynthetic hypothesis: asset custody manipulation affecting stockpile logistics (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-020 — evidence-package-substitution reviewedSynthetic hypothesis: evidence package substitution affecting lab operations (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-021 — download-authorization-bypass pendingSynthetic hypothesis: download authorization bypass affecting patient continuity (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-022 — dependency-compromise pending AI-suggestedSynthetic hypothesis: dependency compromise affecting restricted patient locator (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-023 — supply-chain-compromise reviewedSynthetic hypothesis: supply chain compromise affecting asset management (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-024 — misconfiguration pendingSynthetic hypothesis: misconfiguration affecting program performance (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-025 — availability-disruption pending AI-suggestedSynthetic hypothesis: availability disruption affecting ai intelligence (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-026 — synchronization-abuse reviewedSynthetic hypothesis: synchronization abuse affecting country rollout (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-027 — ai-prompt-or-output-misuse pendingSynthetic hypothesis: ai prompt or output misuse affecting authorized review room (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-028 — ai-generated-false-evidence pending AI-suggestedSynthetic hypothesis: ai generated false evidence affecting executive review packet (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-029 — privilege-escalation reviewedSynthetic hypothesis: privilege escalation affecting identity access governance (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
- TS-030 — insecure-exception-use pendingSynthetic hypothesis: insecure exception use affecting data quality reconciliation (governance scenario only). · hypothesis: yes · proof of attack: no · becomes finding only after human review
Vulnerability findings (finding ≠ confirmed vulnerability; severity ≠ exploitability)
Synthetic discovery only. Missing evidence blocks verified status; false positives and duplicates remain visible; closure requires validation; later closure does not erase history; reopened findings remain visible; accepted risk is not remediation; expired exceptions cannot remain active. Exploitability labels are not exploit instructions.
| Finding | Severity / state | FP / dup / reopened | Posture / audit |
|---|---|---|---|
| VF-001 fund-accountability · authorization |
low unreviewed verify unverified · exploitability theoretical-synthetic |
evidence missing |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-001 |
| VF-002 stockpile-logistics · session |
medium pending-verification verify unverified · exploitability unlikely-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-002 |
| VF-003 lab-operations · input-validation |
high verified verify verified · exploitability conditional-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-003 |
| VF-004 patient-continuity · privilege |
critical false-positive verify not-a-vulnerability · exploitability theoretical-synthetic |
false-positive evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-004 |
| VF-005 restricted-patient-locator · logging |
low duplicate verify unverified · exploitability unlikely-synthetic |
duplicate evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-005 |
| VF-006 asset-management · dependency |
medium remediation-planned verify unverified · exploitability conditional-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-006 |
| VF-007 program-performance · configuration |
high remediation-in-progress verify unverified · exploitability theoretical-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-007 |
| VF-008 ai-intelligence · exception |
critical remediated-pending-validation verify verified · exploitability unlikely-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-008 |
| VF-009 country-rollout · data-minimization |
low validated-closed verify verified · exploitability conditional-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-009 |
| VF-010 authorized-review-room · interface-exposure |
medium risk-accepted verify unverified · exploitability theoretical-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-010 |
| VF-011 executive-review-packet · audit-integrity |
high exception-active verify unverified · exploitability unlikely-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-011 |
| VF-012 identity-access-governance · authorization |
critical expired-exception verify unverified · exploitability conditional-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-012 |
| VF-013 data-quality-reconciliation · session |
low reopened verify unverified · exploitability theoretical-synthetic |
reopened evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-013 |
| VF-014 risk-incident-case-governance · input-validation |
medium blocked-insufficient-evidence verify unverified · exploitability unlikely-synthetic |
evidence missing |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-014 |
| VF-015 policy-compliance-control-governance · privilege |
high not-applicable verify unverified · exploitability conditional-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-015 |
| VF-016 service-reliability-continuity · logging |
critical unreviewed verify unverified · exploitability theoretical-synthetic |
evidence missing |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-016 |
| VF-017 interoperability-data-exchange-governance · dependency |
low pending-verification verify unverified · exploitability unlikely-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-017 |
| VF-018 fund-accountability · configuration |
medium verified verify verified · exploitability conditional-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-018 |
| VF-019 stockpile-logistics · exception |
high false-positive verify not-a-vulnerability · exploitability theoretical-synthetic |
false-positive evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-019 |
| VF-020 lab-operations · data-minimization |
critical duplicate verify unverified · exploitability unlikely-synthetic |
duplicate evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-020 |
| VF-021 patient-continuity · interface-exposure |
low remediation-planned verify unverified · exploitability conditional-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-021 |
| VF-022 restricted-patient-locator · audit-integrity |
medium remediation-in-progress verify unverified · exploitability theoretical-synthetic |
evidence present |
severity ≠ exploitability · missing evidence blocks verified · closure requires validation · later closure does not erase history · audit AE-022 |
Dependency risks (no registry queried; no live CVE feed)
- DR-001 — synthetic-pkg-01 direct-dependency lowversion age current-synthetic (not proof of vuln) · external registry queried: no · live CVE feed: no · upgrade performed: no
- DR-002 — synthetic-pkg-02 transitive-dependency mediumversion age outdated-synthetic (not proof of vuln) · external registry queried: no · live CVE feed: no · upgrade performed: no
- DR-003 — synthetic-pkg-03 outdated-dependency high unknown provenanceversion age deprecated-synthetic (not proof of vuln) · external registry queried: no · live CVE feed: no · upgrade performed: no
- DR-004 — synthetic-pkg-04 unsupported-dependency lowversion age current-synthetic (not proof of vuln) · external registry queried: no · live CVE feed: no · upgrade performed: no
- DR-005 — synthetic-pkg-05 deprecated-package mediumversion age outdated-synthetic (not proof of vuln) · external registry queried: no · live CVE feed: no · upgrade performed: no
- DR-006 — synthetic-pkg-06 unknown-provenance high unknown provenanceversion age deprecated-synthetic (not proof of vuln) · external registry queried: no · live CVE feed: no · upgrade performed: no
- DR-007 — synthetic-pkg-07 integrity-review-pending lowversion age current-synthetic (not proof of vuln) · external registry queried: no · live CVE feed: no · upgrade performed: no
- DR-008 — synthetic-pkg-08 license-review-pending mediumversion age outdated-synthetic (not proof of vuln) · external registry queried: no · live CVE feed: no · upgrade performed: no
- DR-009 — synthetic-pkg-09 maintainer-risk-review high unknown provenanceversion age deprecated-synthetic (not proof of vuln) · external registry queried: no · live CVE feed: no · upgrade performed: no
- DR-010 — synthetic-pkg-10 build-process-risk lowversion age current-synthetic (not proof of vuln) · external registry queried: no · live CVE feed: no · upgrade performed: no
Supply-chain risks (suspicion ≠ finding)
- SC-001 — release-artifact-riskSynthetic supply-chain governance scenario: release artifact risk (no live feed, no registry query). · governance scenario only · suspicion is not a finding: yes · requires human review
- SC-002 — package-substitution-riskSynthetic supply-chain governance scenario: package substitution risk (no live feed, no registry query). · governance scenario only · suspicion is not a finding: yes · requires human review
- SC-003 — dependency-confusion-governance-scenarioSynthetic supply-chain governance scenario: dependency confusion governance scenario (no live feed, no registry query). · governance scenario only · suspicion is not a finding: yes · requires human review
- SC-004 — compromised-update-governance-scenarioSynthetic supply-chain governance scenario: compromised update governance scenario (no live feed, no registry query). · governance scenario only · suspicion is not a finding: yes · requires human review
- SC-005 — maintainer-risk-reviewSynthetic supply-chain governance scenario: maintainer risk review (no live feed, no registry query). · governance scenario only · suspicion is not a finding: yes · requires human review
- SC-006 — release-artifact-riskSynthetic supply-chain governance scenario: release artifact risk (no live feed, no registry query). · governance scenario only · suspicion is not a finding: yes · requires human review
Secure configuration reviews (no config read or changed; secure label ≠ secure implementation)
- CR-001 — secure-defaults secure-labelsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-002 — unnecessary-feature-exposure gap-identifiedsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-003 — authentication-enforcement unknownsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-004 — authorization-enforcement secure-labelsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-005 — role-boundaries partialsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-006 — privileged-functions secure-labelsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-007 — session-governance gap-identifiedsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-008 — audit-logging unknownsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-009 — error-disclosure secure-labelsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-010 — rate-limit-governance-label partialsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-011 — transport-security-governance-label secure-labelsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-012 — secrets-handling-governance-label gap-identifiedsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-013 — environment-separation unknownsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-014 — backup-access-governance secure-labelsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-015 — offline-mode-restrictions partialsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-016 — data-export-restrictions secure-labelsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-017 — controlled-download-restrictions gap-identifiedsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-018 — interface-activation-restrictions unknownsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
- CR-019 — ai-action-restrictions secure-labelsynthetic records · actual server config read: no · infra changed: no · secure label ≠ secure implementation · missing evidence blocks approval
Security testing (six result states; missing evidence blocks pass)
Safe synthetic review methods only — no exploit payloads, attack commands, active scanning, credential attempts, destructive tests, or production probing. A passed review does not prove absence of vulnerabilities; testing does not authorize production deployment; not-tested is distinct from not-applicable; partial remains partial; blocked remains visible; failed tests remain visible after retest; retests append history; the tester cannot independently approve final high-risk conclusions.
| Test | Result | Posture |
|---|---|---|
| TR-001 secure-configuration-review · ST-001 |
pass evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester fund-accountability-security-tester ≠ approver fund-accountability-independent-reviewer |
| TR-002 access-control-review · ST-002 |
partial evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester stockpile-logistics-security-tester ≠ approver stockpile-logistics-independent-reviewer |
| TR-003 privilege-review · ST-003 |
fail evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester lab-operations-security-tester ≠ approver lab-operations-independent-reviewer |
| TR-004 authorization-boundary-review · ST-004 |
blocked evidence present: no |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester patient-continuity-security-tester ≠ approver patient-continuity-independent-reviewer |
| TR-005 session-governance-review · ST-005 |
not-tested evidence present: no |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester restricted-patient-locator-security-tester ≠ approver restricted-patient-locator-independent-reviewer |
| TR-006 input-validation-review · ST-006 |
not-applicable evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester asset-management-security-tester ≠ approver asset-management-independent-reviewer |
| TR-007 output-encoding-review · ST-007 |
pass evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester program-performance-security-tester ≠ approver program-performance-independent-reviewer |
| TR-008 data-minimization-review · ST-008 |
partial evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester ai-intelligence-security-tester ≠ approver ai-intelligence-independent-reviewer |
| TR-009 minimum-necessary-review · ST-009 |
fail evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester country-rollout-security-tester ≠ approver country-rollout-independent-reviewer |
| TR-010 logging-coverage-review · ST-010 |
blocked evidence present: no |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester authorized-review-room-security-tester ≠ approver authorized-review-room-independent-reviewer |
| TR-011 audit-integrity-review · ST-011 |
not-tested evidence present: no |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester executive-review-packet-security-tester ≠ approver executive-review-packet-independent-reviewer |
| TR-012 dependency-review-simulation · ST-012 |
not-applicable evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester identity-access-governance-security-tester ≠ approver identity-access-governance-independent-reviewer |
| TR-013 supply-chain-review-simulation · ST-013 |
pass evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester data-quality-reconciliation-security-tester ≠ approver data-quality-reconciliation-independent-reviewer |
| TR-014 interface-exposure-review · ST-014 |
partial evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester risk-incident-case-governance-security-tester ≠ approver risk-incident-case-governance-independent-reviewer |
| TR-015 version-compatibility-security-review · ST-015 |
fail evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester policy-compliance-control-governance-security-tester ≠ approver policy-compliance-control-governance-independent-reviewer |
| TR-016 backup-security-governance-review · ST-016 |
blocked evidence present: no |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester service-reliability-continuity-security-tester ≠ approver service-reliability-continuity-independent-reviewer |
| TR-017 recovery-security-governance-review · ST-017 |
not-tested evidence present: no |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester interoperability-data-exchange-governance-security-tester ≠ approver interoperability-data-exchange-governance-independent-reviewer |
| TR-018 exception-control-review · ST-018 |
not-applicable evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester fund-accountability-security-tester ≠ approver fund-accountability-independent-reviewer |
| TR-019 secure-change-review · ST-019 |
pass evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester stockpile-logistics-security-tester ≠ approver stockpile-logistics-independent-reviewer |
| TR-020 synthetic-tabletop-exercise · ST-020 |
partial evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester lab-operations-security-tester ≠ approver lab-operations-independent-reviewer |
| TR-021 secure-configuration-review · ST-001 |
fail retest of TR-001 (prior fail) evidence present: yes |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester patient-continuity-security-tester ≠ approver patient-continuity-independent-reviewer |
| TR-022 access-control-review · ST-002 |
blocked retest of TR-002 (prior fail) evidence present: no |
passed review ≠ absence of vulnerabilities · testing ≠ production authorization · missing evidence blocks pass · failed tests remain visible after retest · tester restricted-patient-locator-security-tester ≠ approver restricted-patient-locator-independent-reviewer |
Security events & incidents (event ≠ incident; containment ≠ eradication ≠ recovery)
An event is not automatically an incident; an alert is not proof of attack; an anomaly is not proof of compromise. Incident declaration requires a human decision; data exposure remains unknown when evidence is insufficient; containment does not prove eradication; eradication does not prove recovery; recovery does not erase incident history; closure requires criteria and approval; external notification requires separate authorized review; no real notification occurs.
Synthetic security events
- SE-001 — unauthorized-access event-onlyfund-accountability · confidence low · event is not incident · alert is not proof of attack · review pending
- SE-002 — excessive-privilege triage-pendingstockpile-logistics · confidence medium · event is not incident · alert is not proof of attack · review reviewed
- SE-003 — session-misuse investigation-pendinglab-operations · confidence high · event is not incident · alert is not proof of attack · review pending
- SE-004 — credential-compromise escalatedpatient-continuity · confidence low · event is not incident · alert is not proof of attack · review pending
- SE-005 — insider-misuse disprovenrestricted-patient-locator · confidence medium · event is not incident · alert is not proof of attack · review reviewed
- SE-006 — data-exposure event-onlyasset-management · confidence high · event is not incident · alert is not proof of attack · review pending
- SE-007 — data-alteration triage-pendingprogram-performance · confidence low · event is not incident · alert is not proof of attack · review pending
- SE-008 — record-deletion-attempt investigation-pendingai-intelligence · confidence medium · event is not incident · alert is not proof of attack · review reviewed
- SE-009 — audit-suppression-attempt escalatedcountry-rollout · confidence high · event is not incident · alert is not proof of attack · review pending
- SE-010 — duplicate-or-replay-activity disprovenauthorized-review-room · confidence low · event is not incident · alert is not proof of attack · review pending
- SE-011 — interface-spoofing event-onlyexecutive-review-packet · confidence medium · event is not incident · alert is not proof of attack · review reviewed
- SE-012 — message-tampering triage-pendingidentity-access-governance · confidence high · event is not incident · alert is not proof of attack · review pending
| Incident | State / severity | Containment / eradication / recovery | Posture / audit |
|---|---|---|---|
| SI-001 fund-accountability · unauthorized-access |
event-only low declaration not-declared |
containment not-contained eradication pending recovery pending data exposure none-confirmed-synthetic |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-001 |
| SI-002 stockpile-logistics · excessive-privilege |
triage-pending medium declaration not-declared |
containment not-contained eradication pending recovery pending data exposure unknown-insufficient-evidence |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-002 |
| SI-003 lab-operations · session-misuse |
investigation-pending high declaration not-declared |
containment not-contained eradication pending recovery pending data exposure possible-unconfirmed |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-003 |
| SI-004 patient-continuity · credential-compromise |
incident-declared critical declaration human-declared |
containment not-contained eradication pending recovery pending data exposure none-confirmed-synthetic |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-004 |
| SI-005 restricted-patient-locator · insider-misuse |
contained low declaration human-declared |
containment contained-synthetic eradication pending recovery pending data exposure unknown-insufficient-evidence |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-005 |
| SI-006 asset-management · data-exposure |
eradication-pending medium declaration human-declared |
containment contained-synthetic eradication pending recovery pending data exposure possible-unconfirmed |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-006 |
| SI-007 program-performance · data-alteration |
recovery-pending high declaration human-declared |
containment contained-synthetic eradication eradicated-synthetic recovery pending data exposure none-confirmed-synthetic |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-007 |
| SI-008 ai-intelligence · record-deletion-attempt |
monitoring critical declaration human-declared |
containment contained-synthetic eradication eradicated-synthetic recovery recovered-synthetic data exposure unknown-insufficient-evidence |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-008 |
| SI-009 country-rollout · audit-suppression-attempt |
closure-pending low declaration human-declared |
containment contained-synthetic eradication eradicated-synthetic recovery recovered-synthetic data exposure possible-unconfirmed |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-009 |
| SI-010 authorized-review-room · duplicate-or-replay-activity |
closed-after-approval medium declaration human-declared |
containment contained-synthetic eradication eradicated-synthetic recovery recovered-synthetic data exposure none-confirmed-synthetic |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-010 |
| SI-011 executive-review-packet · interface-spoofing |
reopened high declaration human-declared |
containment not-contained eradication pending recovery pending data exposure unknown-insufficient-evidence |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-011 |
| SI-012 identity-access-governance · message-tampering |
blocked-insufficient-evidence critical declaration not-declared |
containment not-contained eradication pending recovery pending data exposure unknown-insufficient-evidence |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-012 |
| SI-013 data-quality-reconciliation · stale-authorization |
disproven low declaration not-declared |
containment not-contained eradication pending recovery pending data exposure none-confirmed-synthetic |
event ≠ incident · declaration requires human decision · containment ≠ eradication ≠ recovery · closure requires criteria + approval · notification review separate · audit AE-013 |
Containment, eradication & recovery actions (recommendation-only)
Recommendations do not execute actions. This module cannot disable accounts, revoke privileges, rotate credentials, change infrastructure, suspend production interfaces, restart services, or notify external parties — execution remains with authorized operational teams.
- CAC-001 — containment access-review recommendedrecommendation only: no · executes action: no · owner fund-accountability-containment-operator ≠ certifier fund-accountability-independent-certifier
- CAC-002 — containment privilege-review under-reviewrecommendation only: no · executes action: no · owner stockpile-logistics-containment-operator ≠ certifier stockpile-logistics-independent-certifier
- CAC-003 — containment session-invalidation-recommendation-only completed-recommendationrecommendation only: yes · executes action: no · owner lab-operations-containment-operator ≠ certifier lab-operations-independent-certifier
- CAC-004 — containment credential-rotation-recommendation-only pendingrecommendation only: yes · executes action: no · owner patient-continuity-containment-operator ≠ certifier patient-continuity-independent-certifier
- CAC-005 — containment interface-suspension-recommendation-only recommendedrecommendation only: yes · executes action: no · owner restricted-patient-locator-containment-operator ≠ certifier restricted-patient-locator-independent-certifier
- CAC-006 — containment configuration-correction-recommendation-only under-reviewrecommendation only: yes · executes action: no · owner asset-management-containment-operator ≠ certifier asset-management-independent-certifier
- CAC-007 — containment dependency-update-recommendation-only completed-recommendationrecommendation only: yes · executes action: no · owner program-performance-containment-operator ≠ certifier program-performance-independent-certifier
- CAC-008 — containment evidence-preservation pendingrecommendation only: no · executes action: no · owner ai-intelligence-containment-operator ≠ certifier ai-intelligence-independent-certifier
- CAC-009 — containment enhanced-monitoring-recommendation-only recommendedrecommendation only: yes · executes action: no · owner country-rollout-containment-operator ≠ certifier country-rollout-independent-certifier
- ERA-001 — eradication configuration-correction-recommendation-only recommendedrecommendation only: yes · executes action: no · owner fund-accountability-eradication-operator ≠ certifier fund-accountability-independent-certifier
- ERA-002 — eradication dependency-update-recommendation-only under-reviewrecommendation only: yes · executes action: no · owner stockpile-logistics-eradication-operator ≠ certifier stockpile-logistics-independent-certifier
- ERA-003 — eradication evidence-preservation completed-recommendationrecommendation only: no · executes action: no · owner lab-operations-eradication-operator ≠ certifier lab-operations-independent-certifier
- ERA-004 — eradication enhanced-monitoring-recommendation-only pendingrecommendation only: yes · executes action: no · owner patient-continuity-eradication-operator ≠ certifier patient-continuity-independent-certifier
- ERA-005 — eradication data-integrity-review recommendedrecommendation only: no · executes action: no · owner restricted-patient-locator-eradication-operator ≠ certifier restricted-patient-locator-independent-certifier
- ERA-006 — eradication reconciliation-review under-reviewrecommendation only: no · executes action: no · owner asset-management-eradication-operator ≠ certifier asset-management-independent-certifier
- ERA-007 — eradication recovery-validation completed-recommendationrecommendation only: no · executes action: no · owner program-performance-eradication-operator ≠ certifier program-performance-independent-certifier
- REC-001 — recovery data-integrity-review recommendedrecommendation only: no · executes action: no · owner fund-accountability-recovery-operator ≠ certifier fund-accountability-independent-certifier
- REC-002 — recovery reconciliation-review under-reviewrecommendation only: no · executes action: no · owner stockpile-logistics-recovery-operator ≠ certifier stockpile-logistics-independent-certifier
- REC-003 — recovery recovery-validation completed-recommendationrecommendation only: no · executes action: no · owner lab-operations-recovery-operator ≠ certifier lab-operations-independent-certifier
- REC-004 — recovery continuity-activation-review pendingrecommendation only: no · executes action: no · owner patient-continuity-recovery-operator ≠ certifier patient-continuity-independent-certifier
- REC-005 — recovery affected-party-notification-review recommendedrecommendation only: no · executes action: no · owner restricted-patient-locator-recovery-operator ≠ certifier restricted-patient-locator-independent-certifier
- REC-006 — recovery legal-or-regulatory-referral-review under-reviewrecommendation only: no · executes action: no · owner asset-management-recovery-operator ≠ certifier asset-management-independent-certifier
- REC-007 — recovery training-action completed-recommendationrecommendation only: no · executes action: no · owner program-performance-recovery-operator ≠ certifier program-performance-independent-certifier
- REC-008 — recovery control-redesign pendingrecommendation only: no · executes action: no · owner ai-intelligence-recovery-operator ≠ certifier ai-intelligence-independent-certifier
- REC-009 — recovery policy-update recommendedrecommendation only: no · executes action: no · owner country-rollout-recovery-operator ≠ certifier country-rollout-independent-certifier
Risk acceptances (acceptance ≠ remediation; owner cannot self-approve)
- RA-001 — approvedacceptance ≠ remediation · owner fund-accountability-risk-owner cannot approve own · effective 2026-01-01 · expires 2027-01-01 · active: yes · audit AE-001
- RA-002 — pendingacceptance ≠ remediation · owner stockpile-logistics-risk-owner cannot approve own · effective 2026-02-01 · expires 2027-02-01 · active: no · audit AE-002
- RA-003 — approvedacceptance ≠ remediation · owner lab-operations-risk-owner cannot approve own · effective 2026-03-01 · expires 2027-03-01 · active: yes · audit AE-003
- RA-004 — rejectedacceptance ≠ remediation · owner patient-continuity-risk-owner cannot approve own · effective 2026-04-01 · expires 2027-04-01 · active: no · audit AE-004
- RA-005 — approvedacceptance ≠ remediation · owner restricted-patient-locator-risk-owner cannot approve own · effective 2026-05-01 · expires 2027-05-01 · active: no · audit AE-005
- RA-006 — approvedacceptance ≠ remediation · owner asset-management-risk-owner cannot approve own · effective 2026-06-01 · expires 2026-02-01 · active: no · audit AE-006
Security exceptions (time-bound, revocable, no self-approval)
- EXC-001 — security-control-exception approvedactive: yes · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2027-01-01
- EXC-002 — configuration-exception approvedactive: yes · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2027-02-01
- EXC-003 — access-exception expiredactive: no · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2026-03-01
- EXC-004 — privilege-exception rejectedactive: no · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2027-04-01
- EXC-005 — testing-exception withdrawnactive: no · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2027-05-01
- EXC-006 — vulnerability-remediation-exception pendingactive: no · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2027-06-01
- EXC-007 — dependency-exception approvedactive: yes · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2027-01-01
- EXC-008 — logging-exception expiredactive: no · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2026-03-01
- EXC-009 — continuity-security-exception approvedactive: yes · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2027-03-01
- EXC-010 — interface-security-exception rejectedactive: no · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2027-04-01
- EXC-011 — data-protection-exception withdrawnactive: no · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2027-05-01
- EXC-012 — disclosure-exception approvedactive: yes · attributable/scoped/time-bound/revocable/monitored/audited · no self-approval · expires 2027-06-01
Remediation (completion ≠ effectiveness)
- RM-001 — configuration-correction planned pendingcompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual low · linked VF-001 · audit AE-001
- RM-002 — code-correction-synthetic in-progress effectivecompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual medium · linked SR-002 · audit AE-002
- RM-003 — dependency-update-recommendation completed ineffectivecompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual high · linked TR-003 · audit AE-003
- RM-004 — privilege-reduction completed pendingcompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual low · linked SE-004 · audit AE-004
- RM-005 — access-review overdue overdue pendingcompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual medium · linked SI-005 · audit AE-005
- RM-006 — logging-improvement reopened effectivecompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual high · linked EXC-006 · audit AE-006
- RM-007 — data-protection-improvement planned ineffectivecompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual low · linked VF-007 · audit AE-007
- RM-008 — interface-hardening in-progress pendingcompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual medium · linked SR-008 · audit AE-008
- RM-009 — control-redesign completed pendingcompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual high · linked TR-009 · audit AE-009
- RM-010 — procedure-update completed effectivecompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual low · linked SE-010 · audit AE-010
- RM-011 — training overdue overdue ineffectivecompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual medium · linked SI-011 · audit AE-011
- RM-012 — monitoring-improvement reopened pendingcompletion ≠ effectiveness · owner cannot validate high-risk effectiveness · residual high · linked EXC-012 · audit AE-012
Disclosure reviews (review ≠ notification; no real notification occurs)
- DIS-001 — internal-security-leadership pendingno real notification occurs · review is not notification · legal/regulatory determinations outside module · denials do not reveal restricted record existence
- DIS-002 — executive-leadership reviewedno real notification occurs · review is not notification · legal/regulatory determinations outside module · denials do not reveal restricted record existence
- DIS-003 — privacy-review blocked-insufficient-evidenceno real notification occurs · review is not notification · legal/regulatory determinations outside module · denials do not reveal restricted record existence
- DIS-004 — legal-review not-required-syntheticno real notification occurs · review is not notification · legal/regulatory determinations outside module · denials do not reveal restricted record existence
- DIS-005 — regulatory-review pendingno real notification occurs · review is not notification · legal/regulatory determinations outside module · denials do not reveal restricted record existence
- DIS-006 — funder-review reviewedno real notification occurs · review is not notification · legal/regulatory determinations outside module · denials do not reveal restricted record existence
- DIS-007 — partner-review blocked-insufficient-evidenceno real notification occurs · review is not notification · legal/regulatory determinations outside module · denials do not reveal restricted record existence
- DIS-008 — affected-program-review not-required-syntheticno real notification occurs · review is not notification · legal/regulatory determinations outside module · denials do not reveal restricted record existence
- DIS-009 — affected-facility-review pendingno real notification occurs · review is not notification · legal/regulatory determinations outside module · denials do not reveal restricted record existence
- DIS-010 — affected-country-review reviewedno real notification occurs · review is not notification · legal/regulatory determinations outside module · denials do not reveal restricted record existence
Notification decisions (insufficient evidence blocks)
- ND-001 — blocked-insufficient-evidenceno real notification occurs · requires authorized human review · insufficient evidence blocks decision
- ND-002 — pending-authorized-reviewno real notification occurs · requires authorized human review · insufficient evidence blocks decision
- ND-003 — deferredno real notification occurs · requires authorized human review · insufficient evidence blocks decision
- ND-004 — blocked-insufficient-evidenceno real notification occurs · requires authorized human review · insufficient evidence blocks decision
- ND-005 — blocked-insufficient-evidenceno real notification occurs · requires authorized human review · insufficient evidence blocks decision
- ND-006 — pending-authorized-reviewno real notification occurs · requires authorized human review · insufficient evidence blocks decision
Separation-of-duties rules
Violations remain blocked or pending, identify the violated rule, require reassignment, independent review, or second review, remain auditable, and are never silently overridden.
| Rule | Enforcement | Override / audit |
|---|---|---|
| Threat-model author cannot independently approve the final threat model. SOD-01 · threat-model-author-cannot-approve-final-threat-model |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Security-risk owner cannot independently accept their own risk. SOD-02 · security-risk-owner-cannot-accept-own-risk |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Vulnerability reporter cannot independently verify the finding. SOD-03 · vulnerability-reporter-cannot-verify-finding |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Vulnerability verifier cannot independently approve closure. SOD-04 · vulnerability-verifier-cannot-approve-closure |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Remediation owner cannot independently validate high-risk effectiveness. SOD-05 · remediation-owner-cannot-validate-high-risk-effectiveness |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Test performer cannot independently approve final high-risk results. SOD-06 · test-performer-cannot-approve-final-high-risk-results |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Configuration reviewer cannot independently approve their own exception. SOD-07 · configuration-reviewer-cannot-approve-own-exception |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Privileged-access owner cannot independently certify privilege appropriateness. SOD-08 · privileged-access-owner-cannot-certify-privilege-appropriateness |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Identity approver cannot independently certify security recovery. SOD-09 · identity-approver-cannot-certify-security-recovery |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Interface owner cannot independently approve interface-security activation. SOD-10 · interface-owner-cannot-approve-interface-security-activation |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Dependency owner cannot independently certify supply-chain safety. SOD-11 · dependency-owner-cannot-certify-supply-chain-safety |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Incident reporter cannot independently declare the incident. SOD-12 · incident-reporter-cannot-declare-incident |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Incident commander cannot independently approve final closure. SOD-13 · incident-commander-cannot-approve-final-closure |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Containment operator cannot independently certify eradication. SOD-14 · containment-operator-cannot-certify-eradication |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Recovery operator cannot independently certify final recovery. SOD-15 · recovery-operator-cannot-certify-final-recovery |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Evidence collector cannot independently certify evidence integrity. SOD-16 · evidence-collector-cannot-certify-evidence-integrity |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Disclosure requestor cannot independently approve notification. SOD-17 · disclosure-requestor-cannot-approve-notification |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Exception requestor cannot independently approve exception. SOD-18 · exception-requestor-cannot-approve-exception |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Risk-acceptance requestor cannot independently approve acceptance. SOD-19 · risk-acceptance-requestor-cannot-approve-acceptance |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| AI signal generator cannot declare incidents, verify vulnerabilities, accept risks, close findings, execute containment, or notify parties. SOD-20 · ai-generator-cannot-declare-verify-accept-close-contain-notify |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Fund-accountability owner cannot independently approve financial-security conclusions. SOD-21 · fund-owner-cannot-approve-financial-security-conclusions |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Warehouse operator cannot independently certify commodity-security recovery. SOD-22 · warehouse-operator-cannot-certify-commodity-security-recovery |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Laboratory operator cannot independently certify laboratory-security recovery. SOD-23 · laboratory-operator-cannot-certify-laboratory-security-recovery |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Patient-continuity operator cannot independently certify continuity-security recovery. SOD-24 · patient-continuity-operator-cannot-certify-continuity-security-recovery |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Restricted-locator requestor cannot independently approve locator-security disclosure. SOD-25 · restricted-locator-requestor-cannot-approve-locator-security-disclosure |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Asset custodian cannot independently certify asset-security reconciliation. SOD-26 · asset-custodian-cannot-certify-asset-security-reconciliation |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Program submitter cannot independently certify reporting-security integrity. SOD-27 · program-submitter-cannot-certify-reporting-security-integrity |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Rollout assessor cannot independently authorize security readiness. SOD-28 · rollout-assessor-cannot-authorize-security-readiness |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Review-room author cannot independently certify evidence-security readiness. SOD-29 · review-room-author-cannot-certify-evidence-security-readiness |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Packet author cannot independently certify controlled-download security. SOD-30 · packet-author-cannot-certify-controlled-download-security |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Data-quality correction owner cannot independently certify security reconciliation. SOD-31 · data-quality-correction-owner-cannot-certify-security-reconciliation |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Case investigator cannot independently certify security-case closure. SOD-32 · case-investigator-cannot-certify-security-case-closure |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Compliance owner cannot independently attest security-control effectiveness. SOD-33 · compliance-owner-cannot-attest-security-control-effectiveness |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Continuity owner cannot independently certify cyber-recovery readiness. SOD-34 · continuity-owner-cannot-certify-cyber-recovery-readiness |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Interoperability owner cannot independently certify interface-security readiness. SOD-35 · interoperability-owner-cannot-certify-interface-security-readiness |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
Evidence (presence ≠ verification; conflicts remain visible)
- EV-001 — review-record present verified currentfund-accountability · VF-001 · fabricated: no
- EV-002 — assessment-record present unverified currentstockpile-logistics · ST-002 · fabricated: no
- EV-003 — test-record present conflicting supersededlab-operations · SI-003 · fabricated: no
- EV-004 — incident-record present pending stalepatient-continuity · SR-004 · fabricated: no
- EV-005 — config-record missing verified currentrestricted-patient-locator · VF-005 · fabricated: no
- EV-006 — dependency-record present unverified currentasset-management · ST-006 · fabricated: no
- EV-007 — review-record present conflicting supersededprogram-performance · SI-007 · fabricated: no
- EV-008 — assessment-record present pending staleai-intelligence · SR-008 · fabricated: no
- EV-009 — test-record present verified currentcountry-rollout · VF-009 · fabricated: no
- EV-010 — incident-record present unverified currentauthorized-review-room · ST-010 · fabricated: no
- EV-011 — config-record missing conflicting supersededexecutive-review-packet · SI-001 · fabricated: no
- EV-012 — dependency-record present pending staleidentity-access-governance · SR-002 · fabricated: no
AI-assisted security signals (human review required)
- missing-threat-model — Synthetic AI-assisted observation: missing threat model confidence lowhuman review: yes · autonomous action: none
- stale-security-review — Synthetic AI-assisted observation: stale security review confidence mediumhuman review: yes · autonomous action: none
- suggested-threat-scenario — Synthetic AI-assisted observation: suggested threat scenario confidence highhuman review: yes · autonomous action: none
- control-gap — Synthetic AI-assisted observation: control gap confidence lowhuman review: yes · autonomous action: none
- duplicate-vulnerability-finding — Synthetic AI-assisted observation: duplicate vulnerability finding confidence mediumhuman review: yes · autonomous action: none
- missing-evidence — Synthetic AI-assisted observation: missing evidence confidence highhuman review: yes · autonomous action: none
- vulnerability-priority — Synthetic AI-assisted observation: vulnerability priority confidence lowhuman review: yes · autonomous action: none
- overdue-remediation — Synthetic AI-assisted observation: overdue remediation confidence mediumhuman review: yes · autonomous action: none
- remediation-vs-validation-gap — Synthetic AI-assisted observation: remediation vs validation gap confidence highhuman review: yes · autonomous action: none
- privilege-concentration — Synthetic AI-assisted observation: privilege concentration confidence lowhuman review: yes · autonomous action: none
- unusual-access-pattern — Synthetic AI-assisted observation: unusual access pattern confidence mediumhuman review: yes · autonomous action: none
- dependency-concentration — Synthetic AI-assisted observation: dependency concentration confidence highhuman review: yes · autonomous action: none
- unknown-provenance — Synthetic AI-assisted observation: unknown provenance confidence lowhuman review: yes · autonomous action: none
- possible-interface-exposure — Synthetic AI-assisted observation: possible interface exposure confidence mediumhuman review: yes · autonomous action: none
- incident-chronology-summary — Synthetic AI-assisted observation: incident chronology summary confidence highhuman review: yes · autonomous action: none
- inconsistent-incident-state — Synthetic AI-assisted observation: inconsistent incident state confidence lowhuman review: yes · autonomous action: none
- recommend-second-review — Synthetic AI-assisted observation: recommend second review confidence mediumhuman review: yes · autonomous action: none
- expired-acceptance-or-exception — Synthetic AI-assisted observation: expired acceptance or exception confidence highhuman review: yes · autonomous action: none
- potentially-ineffective-remediation — Synthetic AI-assisted observation: potentially ineffective remediation confidence lowhuman review: yes · autonomous action: none
- finding-source-reconciliation — Synthetic AI-assisted observation: finding source reconciliation confidence mediumhuman review: yes · autonomous action: none
Immutable audit events (append-only)
Threat-model version changes, risk reassessments, vulnerability verification, false-positive and duplicate decisions, remediation status changes and validation, finding closure and reopen, risk-acceptance approval/expiration/revocation, exception approval/expiration/revocation, security-test execution and retest, incident declaration, containment/eradication/recovery decisions, notification-review decisions, incident closure and reopen, and disclosure-review decisions all require new linked events. Deletion is not an allowed governance control; this is not a production cryptographic audit ledger.
- AE-001 — threat model version change synthetic-result threat-model-version-changefund-accountability-security-actor · fund-accountability · 2026-01-10T00:30:00Z · immutable: yes
- AE-002 — risk reassessment synthetic-result risk-reassessmentstockpile-logistics-security-actor · stockpile-logistics · 2026-02-11T01:30:00Z · immutable: yes
- AE-003 — vulnerability verification synthetic-result vulnerability-verificationlab-operations-security-actor · lab-operations · 2026-03-12T02:30:00Z · immutable: yes
- AE-004 — false positive decision synthetic-result false-positive-decisionpatient-continuity-security-actor · patient-continuity · 2026-04-13T03:30:00Z · immutable: yes
- AE-005 — duplicate linkage synthetic-result duplicate-linkagerestricted-patient-locator-security-actor · restricted-patient-locator · 2026-05-14T04:30:00Z · immutable: yes
- AE-006 — remediation status change synthetic-result remediation-status-changeasset-management-security-actor · asset-management · 2026-06-15T05:30:00Z · immutable: yes
- AE-007 — remediation validation synthetic-result remediation-validationprogram-performance-security-actor · program-performance · 2026-01-16T06:30:00Z · immutable: yes
- AE-008 — finding closure synthetic-result finding-closureai-intelligence-security-actor · ai-intelligence · 2026-02-17T07:30:00Z · immutable: yes
- AE-009 — finding reopen synthetic-result finding-reopencountry-rollout-security-actor · country-rollout · 2026-03-10T08:30:00Z · immutable: yes
- AE-010 — risk acceptance approval synthetic-result risk-acceptance-approvalauthorized-review-room-security-actor · authorized-review-room · 2026-04-11T00:30:00Z · immutable: yes
- AE-011 — risk acceptance expiration or revocation synthetic-result risk-acceptance-expiration-or-revocationexecutive-review-packet-security-actor · executive-review-packet · 2026-05-12T01:30:00Z · immutable: yes
- AE-012 — exception approval synthetic-result exception-approvalidentity-access-governance-security-actor · identity-access-governance · 2026-06-13T02:30:00Z · immutable: yes
- AE-013 — exception expiration or revocation synthetic-result exception-expiration-or-revocationdata-quality-reconciliation-security-actor · data-quality-reconciliation · 2026-01-14T03:30:00Z · immutable: yes
- AE-014 — security test execution synthetic-result security-test-executionrisk-incident-case-governance-security-actor · risk-incident-case-governance · 2026-02-15T04:30:00Z · immutable: yes
- AE-015 — security retest synthetic-result security-retestpolicy-compliance-control-governance-security-actor · policy-compliance-control-governance · 2026-03-16T05:30:00Z · immutable: yes
- AE-016 — incident declaration synthetic-result incident-declarationservice-reliability-continuity-security-actor · service-reliability-continuity · 2026-04-17T06:30:00Z · immutable: yes
- AE-017 — containment decision synthetic-result containment-decisioninteroperability-data-exchange-governance-security-actor · interoperability-data-exchange-governance · 2026-05-10T07:30:00Z · immutable: yes
- AE-018 — eradication decision synthetic-result eradication-decisionfund-accountability-security-actor · fund-accountability · 2026-06-11T08:30:00Z · immutable: yes
- AE-019 — recovery decision synthetic-result recovery-decisionstockpile-logistics-security-actor · stockpile-logistics · 2026-01-12T00:30:00Z · immutable: yes
- AE-020 — notification review decision synthetic-result notification-review-decisionlab-operations-security-actor · lab-operations · 2026-02-13T01:30:00Z · immutable: yes
- AE-021 — incident closure synthetic-result incident-closurepatient-continuity-security-actor · patient-continuity · 2026-03-14T02:30:00Z · immutable: yes
- AE-022 — incident reopen synthetic-result incident-reopenrestricted-patient-locator-security-actor · restricted-patient-locator · 2026-04-15T03:30:00Z · immutable: yes
- AE-023 — disclosure review decision synthetic-result disclosure-review-decisionasset-management-security-actor · asset-management · 2026-05-16T04:30:00Z · immutable: yes
By module
- fund-accountability 2
- stockpile-logistics 2
- lab-operations 2
- patient-continuity 1
- restricted-patient-locator 1
- asset-management 1
- program-performance 1
- ai-intelligence 1
- country-rollout 1
- authorized-review-room 1
- executive-review-packet 1
- identity-access-governance 1
- data-quality-reconciliation 1
- risk-incident-case-governance 1
- policy-compliance-control-governance 1
- service-reliability-continuity 1
- interoperability-data-exchange-governance 1
By asset category
- application 4
- api-interface 4
- data-store-governance-label 4
- batch-process 4
- dashboard 4
By security domain / risk
- governance 1
- identity-and-access 1
- authentication 1
- authorization 1
- privileged-access 1
- application-security 1
- api-and-interface-security 1
- data-protection 1
- privacy 1
- encryption-governance 1
- key-management-governance-label 1
- secrets-management-governance-label 1
- infrastructure-security 1
- network-security 1
By threat category
- unauthorized-access 1
- excessive-privilege 1
- session-misuse 1
- credential-compromise 1
- insider-misuse 1
- data-exposure 1
- data-alteration 1
- record-deletion-attempt 1
- audit-suppression-attempt 1
- duplicate-or-replay-activity 1
- interface-spoofing 1
- message-tampering 1
- stale-authorization 1
- consent-status-misuse 1
- restricted-locator-misuse 1
- commodity-diversion-concealment 1
- laboratory-result-alteration 1
- program-result-manipulation 1
- asset-custody-manipulation 1
- evidence-package-substitution 1
- download-authorization-bypass 1
- dependency-compromise 1
- supply-chain-compromise 1
- misconfiguration 1
- availability-disruption 1
- synchronization-abuse 1
- ai-prompt-or-output-misuse 1
- ai-generated-false-evidence 1
- privilege-escalation 1
- insecure-exception-use 1
By vulnerability severity
- low 6
- medium 6
- high 5
- critical 5
By finding state
- unreviewed 2
- pending-verification 2
- verified 2
- false-positive 2
- duplicate 2
- remediation-planned 2
- remediation-in-progress 2
- remediated-pending-validation 1
- validated-closed 1
- risk-accepted 1
- exception-active 1
- expired-exception 1
- reopened 1
- blocked-insufficient-evidence 1
- not-applicable 1
By test result
- pass 4
- partial 4
- fail 4
- blocked 4
- not-tested 3
- not-applicable 3
By incident state
- event-only 1
- triage-pending 1
- investigation-pending 1
- incident-declared 1
- contained 1
- eradication-pending 1
- recovery-pending 1
- monitoring 1
- closure-pending 1
- closed-after-approval 1
- reopened 1
- blocked-insufficient-evidence 1
- disproven 1
By risk-acceptance status
- approved 4
- pending 1
- rejected 1
By exception status
- approved 5
- expired 2
- rejected 2
- withdrawn 2
- pending 1
By remediation status
- planned 2
- in-progress 2
- completed 4
- overdue 2
- reopened 2
Module coverage
AI posture — assistive only, non-autonomous
AI assists with
- identify missing threat models
- identify stale security reviews
- suggest threat scenarios
- detect control gaps
- identify duplicate vulnerability findings
- flag missing evidence
- prioritize vulnerabilities by synthetic risk
- identify overdue remediation
- compare remediation with validation evidence
- identify privilege concentration
- identify unusual access-governance patterns
- identify dependency concentration
- flag unknown provenance
- identify possible interface exposure
- summarize incident chronology
- identify inconsistent incident states
- recommend independent or second review
- detect expired acceptances or exceptions
- identify potentially ineffective remediation
- reconcile security findings with source-module evidence
AI must never
- scan networks
- scan ports
- exploit vulnerabilities
- generate exploit payloads
- execute malware
- test credentials
- obtain or expose secrets
- call external security systems
- ingest live threat feeds
- declare incidents
- verify vulnerabilities autonomously
- approve severity
- approve closure
- accept risk
- approve exceptions
- disable accounts
- revoke privileges
- rotate credentials
- suspend interfaces
- change configuration
- alter infrastructure
- restart services
- suppress findings
- fabricate evidence
- notify external parties
- authorize disclosure
- bypass human review, evidence, expiration, revocation, separation of duties, or audit controls
AI is assistive only. It may prioritize, summarize, and flag for authorized human reviewers, but never scans, exploits, declares incidents, verifies vulnerabilities, approves severity/closure, accepts risk, approves exceptions, disables accounts, revokes privileges, rotates credentials, suspends interfaces, changes configuration, restarts services, suppresses findings, fabricates evidence, notifies external parties, authorizes disclosure, or bypasses human review, evidence, expiration, revocation, separation of duties, or audit controls.
Runtime boundary & module coverage
- Impact runtime:
impact.maxarchealth.comon127.0.0.1:3201. - Covers cybersecurity, threat, vulnerability, and response governance for all existing modules — without coupling to MaxTrax EHR.
- No network or port scan, exploit, credential test, malware action, log ingestion, packet capture, external security call, live monitoring, real alert/notification, real upload/download, real database write, automated containment, account action, privilege revocation, firewall change, or service restart occurs. No Apache, PM2, systemd, firewall, DNS, TLS, SSH, secrets, credentials, or environment file is read or modified.
- Medical Library boundary remains separate at
library.maxarchealth.com(port3101) and is not used here. - MaxTrax EHR remains separate; this is not a full EHR and implements no live security monitoring, penetration testing, incident response, or infrastructure enforcement.