{"schema":"opensof.oscal-aligned-assessment-results/1.0","note":"OSCAL-aligned export. Validate and transform against the selected OSCAL profile before submission to an authority.","generated_at":"2026-08-28T19:47:01.138Z","assessment-results":{"uuid":"648a42d6-5096-4196-bb14-2a2828c54581","metadata":{"title":"OpenCyberSec Operational Assurance Snapshot","version":"1.0","last_modified":"2026-08-28T19:47:01.138Z","oscal_version":"1.1.3 reference"},"results":[{"uuid":"830f3cdf-157d-4008-89c2-a90c545bceae","title":"OpenCyberSec current-state assessment","description":"Machine-generated operational control observations from OpenC5ISR.","start":"2026-08-26T17:54:25.188Z","end":"2026-08-28T19:47:01.138Z","observations":[{"uuid":"3d253baf-313e-431b-a99e-e3084ac08ab9","title":"Cyber risk governance and ownership","description":"Named owners, risk model, approval policies, and mission-impact prioritization are represented.","methods":["EXAMINE"],"collected":"2026-08-26T17:54:25.188Z","props":[{"name":"opensof-control-id","value":"CTRL-GV-CYBER-RISK"},{"name":"status","value":"PARTIAL"},{"name":"function","value":"GOVERN"}],"relevant_evidence":[]},{"uuid":"1d163fb0-1c12-40f2-b987-bfea781bc528","title":"Semantic asset, identity, and dependency inventory","description":"Assets and dependencies are represented in the OpenKnowledge-compatible graph.","methods":["EXAMINE"],"collected":"2026-08-26T17:54:25.188Z","props":[{"name":"opensof-control-id","value":"CTRL-ID-ASSET-GRAPH"},{"name":"status","value":"PASS"},{"name":"function","value":"IDENTIFY"}],"relevant_evidence":[]},{"uuid":"5da2bbdb-36c3-47e3-86b2-5b3de3a8d5aa","title":"Authenticated mutation interfaces","description":"All state-changing public APIs require an operator or agent credential.","methods":["EXAMINE"],"collected":"2026-08-28T08:17:07.659Z","props":[{"name":"opensof-control-id","value":"CTRL-PR-API-AUTH"},{"name":"status","value":"FAIL"},{"name":"function","value":"PROTECT"}],"relevant_evidence":[{"href":"#EXP-OPENBUS-WRITE-AUTH","description":"EXP-OPENBUS-WRITE-AUTH"},{"href":"#EXP-OPENRF-OPERATOR-AUTH","description":"EXP-OPENRF-OPERATOR-AUTH"},{"href":"#EXP-CYBER-OPERATOR-AUTH","description":"EXP-CYBER-OPERATOR-AUTH"},{"href":"#EXP-CYBER-AGENT-AUTH","description":"EXP-CYBER-AGENT-AUTH"}]},{"uuid":"61ae1b60-0eef-4386-ad33-3f646b5cd1f7","title":"Least privilege for operators, agents, models, and automation","description":"Disruptive response is approval-gated and delegated actions are scoped.","methods":["EXAMINE"],"collected":"2026-08-26T17:54:25.188Z","props":[{"name":"opensof-control-id","value":"CTRL-PR-LEAST-PRIVILEGE"},{"name":"status","value":"PARTIAL"},{"name":"function","value":"PROTECT"}],"relevant_evidence":[]},{"uuid":"5f10ccfa-080d-42e0-b2b4-a35b87ec6627","title":"Normalized, correlated security telemetry","description":"OCSF, OpenBus, STIX, agent, and security-tool observations normalize into common detections.","methods":["EXAMINE"],"collected":"2026-08-26T17:54:25.188Z","props":[{"name":"opensof-control-id","value":"CTRL-DE-NORMALIZATION"},{"name":"status","value":"PARTIAL"},{"name":"function","value":"DETECT"}],"relevant_evidence":[]},{"uuid":"ca58543c-5a2b-439f-bbf9-28f7edc2b63e","title":"ATT&CK-oriented detection coverage management","description":"Rules map priority adversary behaviors to sources and defensive countermeasures.","methods":["EXAMINE"],"collected":"2026-08-26T17:54:25.188Z","props":[{"name":"opensof-control-id","value":"CTRL-DE-COVERAGE"},{"name":"status","value":"PARTIAL"},{"name":"function","value":"DETECT"}],"relevant_evidence":[]},{"uuid":"c729de4c-6806-4567-8c02-75db6bc5d412","title":"Human-approved disruptive response","description":"Containment and remediation are represented as approval-gated OpenTask work.","methods":["EXAMINE"],"collected":"2026-08-26T17:54:25.188Z","props":[{"name":"opensof-control-id","value":"CTRL-RS-PLAYBOOK-GATES"},{"name":"status","value":"PASS"},{"name":"function","value":"RESPOND"}],"relevant_evidence":[]},{"uuid":"62f4c36f-6cd6-4eb7-a3e1-a07ea9d895ae","title":"Hash-chained evidence and provenance","description":"Evidence metadata and content hashes are chained and can use OpenPNT time quality.","methods":["EXAMINE"],"collected":"2026-08-26T17:54:25.188Z","props":[{"name":"opensof-control-id","value":"CTRL-RS-EVIDENCE"},{"name":"status","value":"PASS"},{"name":"function","value":"RESPOND"}],"relevant_evidence":[]},{"uuid":"386531d4-8a79-43f6-912f-4af39b7142b4","title":"Recovery validation and heightened monitoring","description":"Playbooks include restoration, semantic dependency checks, and verification steps.","methods":["EXAMINE"],"collected":"2026-08-26T17:54:25.188Z","props":[{"name":"opensof-control-id","value":"CTRL-RC-VALIDATION"},{"name":"status","value":"PARTIAL"},{"name":"function","value":"RECOVER"}],"relevant_evidence":[]},{"uuid":"4b68ec8f-dfe5-4d73-bab8-6a7f56c36b9d","title":"SBOM, VEX, advisory, and exploitability correlation","description":"SPDX/CycloneDX/CSAF/VEX evidence can be joined to mission assets and exposure priority.","methods":["EXAMINE"],"collected":"2026-08-26T17:54:25.188Z","props":[{"name":"opensof-control-id","value":"CTRL-SC-SBOM-VEX"},{"name":"status","value":"PARTIAL"},{"name":"function","value":"IDENTIFY"}],"relevant_evidence":[]},{"uuid":"3b1cf02d-c7d8-4ffa-9f3e-57908a164286","title":"AI and agent authority boundaries","description":"Models and agents are inventoried with tool scopes, data classes, approvals, and kill switches.","methods":["EXAMINE"],"collected":"2026-08-26T17:54:25.188Z","props":[{"name":"opensof-control-id","value":"CTRL-AI-AUTHORITY"},{"name":"status","value":"PARTIAL"},{"name":"function","value":"GOVERN"}],"relevant_evidence":[]}],"findings":[{"uuid":"3bbe8384-b8fb-4c3a-a777-09a1b5150c4a","title":"OpenBus public mutation authentication","description":"OpenBus mutation endpoints accept writes without a configured API token.","target":{"type":"objective-id","target_id":"EXP-OPENBUS-WRITE-AUTH","status":{"state":"not-satisfied"}},"props":[{"name":"risk-level","value":"MEDIUM"},{"name":"asset-id","value":"OPENBUS"}]}]}]}}