{
  "$note": "ACAM sampling/window/freshness annex, machine-readable half (the minimum-n table, freshness re-cut table, selection-method rules, and deviation rules as data). One release unit with acam/ACAM-SAMPLING.md, acam/ACAM-SPEC.md, and acam/acam-core.json; all version together (ACAM-SPEC V-1). Keys are recursively sorted (deterministic byte form); ASCII only. Rung ceilings use the acam-core ladder order; 'cap at X' means computed rung = min(rung, X). Every published n at a statistically-derived cell is at or above its exact binomial minimum; practice-norm cells claim no statistical inference and carry the cell-level disclaimer.",
  "acam_version": "0.1.0-draft",
  "annex_of": "acam/ACAM-SPEC.md sections 11-12; consumed by CAP-05..CAP-15 and CAP-25",
  "core": "acam/acam-core.json",
  "design_of_record": "COVERAGE_ASSESSMENT_PLAN.md sections 4, 13, 14/B2",
  "deviation_rules": [
    {
      "condition": "A sampling deviation is found.",
      "consequence": "recorded append-only with item identifier, observed condition, and deviation_disposition from the closed enum (isolated-root-caused | systematic | undetermined)",
      "rule_id": "SAMP-19",
      "source": "ANNEX 7; SPEC 11.1"
    },
    {
      "condition": "deviation_disposition is systematic or undetermined.",
      "consequence": "operating sub-state = tested-exception; no extended-testing path inside this window",
      "rule_id": "SAMP-19",
      "source": "ANNEX 7"
    },
    {
      "condition": "Any deviation on a blocking control.",
      "consequence": "failure token tested-exception until a qualifying extended-testing sub-record is appended (the record itself is append-only and immutable per DOM-3; the extension lifts the forcing, never the record)",
      "rule_id": "SAMP-20",
      "source": "CAP-08; ANNEX 7"
    },
    {
      "condition": "Extended-testing sub-record appended: disposition isolated-root-caused with referenced root-cause evidence; second deterministic seeded draw (seed suffix #draw-2, #draw-3, ...) from the same population excluding previously selected items; extension size >= the original minimum-n; zero further deviations; append-only reference to the deviation extended.",
      "consequence": "operating sub-state may record tested-held with the deviation retained and rendered alongside; applies to blocking (lifts CAP-08 forcing) and non-blocking controls alike",
      "rule_id": "SAMP-21",
      "source": "ANNEX 7; CAP-08; DOM-3"
    },
    {
      "condition": "After a qualifying extension: combined sample (original + extensions) contains exactly one deviation AND combined n >= the one-deviation minimum for the band (95 heightened / 40 standard) AND the frequency cell basis is statistically-derived-with-margin (continuous row only).",
      "consequence": "effective is reachable; in every other post-deviation case rung <= tested for the window (practice-norm cells: rung <= tested regardless of extension size)",
      "draft_decision": "D-A2-3",
      "rule_id": "SAMP-22",
      "source": "ANNEX 7"
    },
    {
      "condition": "Two or more deviations in the combined sample.",
      "consequence": "extension path ends for the window; operating sub-state = tested-exception (on blocking controls the CAP-08 token stands unlifted)",
      "rule_id": "SAMP-23",
      "source": "ANNEX 7"
    }
  ],
  "disclaimers": {
    "cell_level_practice_norm": "Samples drawn at this cell's minimum are not statistically valid projections of the population. The cell value is a practice-norm test extent; no confidence or tolerable-deviation statement attaches to it.",
    "rendering_rule": "SAMP-12: every dossier surface rendering a sampling-supported rung renders the table-level disclaimer once and the cell basis marker per control, with the cell-level disclaimer wherever the marker is practice-norm; attaching a confidence or tolerable-deviation figure to a practice-norm cell violates the ACAM-SPEC 16.4 claim-language register.",
    "table_level": "the table reflects practice norms, not standards mandates, and is not represented as statistically valid inference for any particular population"
  },
  "extended_testing": {
    "note": "Minimum COMBINED sample size (original + extensions) for effective after exactly one deviation, at the band's stated parameters; derivation in ACAM-SAMPLING.md Annex A. Applies only where the frequency cell is statistically-derived-with-margin (continuous).",
    "one_deviation_minimums": {
      "heightened": {
        "exact_binomial_minimum": 93,
        "published": 95
      },
      "standard": {
        "exact_binomial_minimum": 38,
        "published": 40
      }
    }
  },
  "freshness": {
    "change_frequency": {
      "enum": [
        "high",
        "moderate",
        "low"
      ],
      "fail_closed_default": "high",
      "meaning": {
        "high": "the evidence subject changes monthly or more often",
        "low": "the evidence subject changes annually or less",
        "moderate": "the evidence subject changes roughly quarterly"
      },
      "rule_id": "SAMP-27"
    },
    "event_rule": {
      "consequence": "event evidence (approvals, tickets, execution logs, incident records - the population items themselves) is never re-cut; admissibility is governed by window rule W1 alone",
      "rule_id": "SAMP-26",
      "source": "ANNEX 9; CAP-09"
    },
    "measurement": "age_days = assessment_window.end - collected_at (window-first; deterministic, no wall clock at assessment time). At verification time the same horizons drive the CAP-25 stale state against the verifier clock.",
    "override": {
      "condition": "Non-blocking control; state item past its horizon by <= 90 days; recorded justification.",
      "consequence": "item retained; every use counted on the dossier cover (CAP-13). No override exists for blocking controls, for W1 (CAP-09), or for interview-notes-as-sole-support (CAP-12).",
      "draft_decision": "D-A2-4",
      "override_id": "OVR-1",
      "rule_id": "SAMP-30",
      "source": "ANNEX 9; CAP-13"
    },
    "stale_consequence": {
      "condition": "State item older than its horizon at assessment_window.end (and no qualifying OVR-1 override).",
      "consequence": "item unsatisfied; rung recomputed without it",
      "rule_id": "SAMP-28",
      "source": "CAP-11; ANNEX 9"
    },
    "state_class_fail_closed_default": "state",
    "table": [
      {
        "basis": "practice-norm",
        "evidence_class": "state-automated",
        "max_age_days": {
          "high": 90,
          "low": 365,
          "moderate": 180
        },
        "meaning": "system-generated state: configuration snapshot, automated inventory or access export",
        "rule_id": "SAMP-28",
        "source": "ANNEX 9"
      },
      {
        "basis": "practice-norm",
        "evidence_class": "state-third-party",
        "max_age_days": {
          "high": 180,
          "low": 365,
          "moderate": 365
        },
        "meaning": "third-party report on state (external audit report, certification, penetration-test report); its own period of coverage must intersect the window",
        "rule_id": "SAMP-28",
        "source": "ANNEX 9"
      },
      {
        "basis": "practice-norm",
        "evidence_class": "state-human",
        "max_age_days": {
          "high": 90,
          "low": 365,
          "moderate": 180
        },
        "meaning": "human-contemporaneous observation of state: walkthrough record, reviewed screenshot-of-record",
        "rule_id": "SAMP-28",
        "source": "ANNEX 9"
      },
      {
        "basis": "practice-norm",
        "evidence_class": "state-attested",
        "max_age_days": {
          "high": 90,
          "low": 365,
          "moderate": 180
        },
        "meaning": "attested document: policy, standard, management representation (reliability-capped separately by CAP-01/CAP-03)",
        "rule_id": "SAMP-28",
        "source": "ANNEX 9"
      }
    ],
    "table_note": "Horizons are practice norms, not statistical derivations; none is claimed as one (draft decision D-A2-4). All horizons are additionally capped by the assessment window; 365 means the whole <=12-month window.",
    "window_first": "Window rules W1/W2 (CAP-09/CAP-10) always bind before any freshness horizon."
  },
  "minimum_n": {
    "assumptions": {
      "expected_deviations": 0,
      "note": "Stated verbatim per the design of record: 5%/10% tolerable deviation (blocking-or-heightened / standard), 0 expected deviations, 95%/90% confidence. Any deviation found means the zero-expected-deviation plan failed and the deviation rules apply.",
      "parameters": {
        "heightened": {
          "confidence": 0.95,
          "tolerable_deviation_rate": 0.05
        },
        "standard": {
          "confidence": 0.9,
          "tolerable_deviation_rate": 0.1
        }
      },
      "rule_id": "SAMP-08"
    },
    "binding": {
      "condition": "Population-governing control with declared frequency f and derived band b.",
      "consequence": "minimum n = min(table cell [f][b], population size); n below minimum => rung <= tested (CAP-05); undeclared frequency selects the continuous row (fail-closed, largest n)",
      "rule_id": "SAMP-10",
      "source": "CAP-05; ANNEX 5"
    },
    "full_population_rule": {
      "condition": "Population size <= the cell value.",
      "consequence": "test the full population (selection_method full-population); satisfies CAP-05 by construction; no sampling inference applies",
      "rule_id": "SAMP-11",
      "source": "ANNEX 5"
    },
    "headline_rule": {
      "condition": "Any control reached effective on a sample below the ACAM minimum.",
      "consequence": "verifier-computed headline 'N controls reached effective on samples below ACAM minimums' is mandatory when non-zero; non-zero => exception class sample-below-minimum-uncapped (non-conforming producer)",
      "rule_id": "SAMP-13",
      "source": "SPEC 11.2; ANNEX 5"
    },
    "statistical_minimums": {
      "note": "Exact binomial minimums for a large population at the stated parameters; derivations in ACAM-SAMPLING.md Annex A. Published values are rounded up; a published value below its exact minimum would be a defect in this standard.",
      "one_deviation": {
        "heightened": 93,
        "standard": 38
      },
      "zero_deviation": {
        "heightened": 59,
        "standard": 22
      }
    },
    "table": [
      {
        "band": "standard",
        "basis": "statistically-derived-with-margin",
        "frequency": "continuous",
        "n": 25,
        "note": "exact binomial minimum 22 at 90%/10%/0-expected; confidence statement holds at 25",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "heightened",
        "basis": "statistically-derived-with-margin",
        "frequency": "continuous",
        "n": 60,
        "note": "exact binomial minimum 59 at 95%/5%/0-expected; confidence statement holds at 60",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "standard",
        "basis": "practice-norm",
        "frequency": "daily",
        "n": 15,
        "note": "below the 22 exact minimum for 90%/10%; practice-norm value; cell-level disclaimer attaches",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "heightened",
        "basis": "practice-norm",
        "frequency": "daily",
        "n": 40,
        "note": "below the 59 exact minimum for 95%/5%; practice-norm value; does NOT support a 95%/5% statement; cell-level disclaimer attaches",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "standard",
        "basis": "practice-norm",
        "frequency": "weekly",
        "n": 5,
        "note": "population ~52 is below the attribute-sampling regime; practice-norm test extent",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "heightened",
        "basis": "practice-norm",
        "frequency": "weekly",
        "n": 10,
        "note": "population ~52 is below the attribute-sampling regime; practice-norm test extent",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "standard",
        "basis": "practice-norm",
        "frequency": "monthly",
        "n": 2,
        "note": "population ~12; practice-norm test extent",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "heightened",
        "basis": "practice-norm",
        "frequency": "monthly",
        "n": 4,
        "note": "population ~12; practice-norm test extent",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "standard",
        "basis": "practice-norm",
        "frequency": "quarterly",
        "n": 2,
        "note": "population ~4; practice-norm test extent",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "heightened",
        "basis": "practice-norm",
        "frequency": "quarterly",
        "n": 2,
        "note": "population ~4; practice-norm test extent",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "standard",
        "basis": "practice-norm",
        "frequency": "annual",
        "n": 1,
        "note": "population ~1; full population where the population is 1",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      },
      {
        "band": "heightened",
        "basis": "practice-norm",
        "frequency": "annual",
        "n": 1,
        "note": "population ~1; full population where the population is 1",
        "rule_id": "SAMP-10",
        "source": "ANNEX 5"
      }
    ],
    "table_key": "frequency (continuous | daily | weekly | monthly | quarterly | annual) x band (standard | heightened per risk_bands.derivation)"
  },
  "population_rules": [
    {
      "condition": "Population-governing control missing any of: population definition, population_enumeration_basis, population size, control frequency, selection method, sample size, deviations found, deviation disposition; or an automated system-of-record count missing ipe_basis.",
      "consequence": "schema-invalid where the field is schema-required; missing population_enumeration_basis => rung <= documented (CAP-06); missing ipe_basis fires exception class ipe-basis-absent",
      "rule_id": "SAMP-01",
      "source": "SPEC 11.1; CAP-06"
    },
    {
      "condition": "Control-level population declarations do not reconcile against the once-declared scoping-header system-of-record counts with typed variances.",
      "consequence": "exception class population-reconciliation fires; reconciliation establishes internal consistency against a declared basis, never population assurance",
      "rule_id": "SAMP-02",
      "source": "SPEC 11.1 D3"
    },
    {
      "condition": "population_enumeration_basis outside the closed enum (provider-api-export | registry-export | cmdb-export | financial-system-tie | interview-assertion | estimate).",
      "consequence": "treated as a missing basis (rung <= documented, CAP-06); there is no 'other' value",
      "rule_id": "SAMP-03",
      "source": "acam-core enums.enumeration_basis; CAP-06"
    },
    {
      "condition": "No corroborating count from a second source where one was obtainable, or population_enumeration_basis = interview-assertion.",
      "consequence": "affected controls <= documented (CAP-14, fail-closed)",
      "rule_id": "SAMP-04",
      "source": "CAP-14; SPEC 11.1"
    },
    {
      "condition": "population_enumeration_basis = estimate.",
      "consequence": "affected controls <= documented (identically to interview-assertion: an estimated population has no enumerable items, so no selection over it is verifiable)",
      "draft_decision": "D-A2-2",
      "rule_id": "SAMP-05",
      "source": "ANNEX 3"
    },
    {
      "condition": "A declared count differs from a reconciled or corroborating count without a variance_reason from the closed enum (timing-difference | scope-boundary-difference | decommissioned-not-yet-removed | provisioning-in-flight | duplicate-record | source-refresh-lag | classification-difference), or the typed variances do not quantitatively account for the difference with linked evidence. Applies equally to sample-size and coverage deviations.",
      "consequence": "treated as missing enumeration basis (<= documented, CAP-15); exception class population-reconciliation fires",
      "rule_id": "SAMP-06",
      "source": "CAP-15; SPEC 11.1; decision D-5 carried forward unchanged"
    },
    {
      "condition": "Automated system-of-record count without ipe_basis.",
      "consequence": "exception class ipe-basis-absent fires",
      "rule_id": "SAMP-07",
      "source": "SPEC 10.1; ANNEX 3"
    }
  ],
  "risk_bands": {
    "derivation": {
      "draft_decision": "D-A2-5",
      "heightened_when_any_of": [
        "the control is a blocking control (blocking_effect = blocks-deployment or blocks-runtime-action)",
        "any declared entity-risk axis (consequence class, autonomy, reversibility, population exposed, regulatory classification - SPEC 14.3; value sets finalize in A5) sits at its maximum ordinal value",
        "any entity-risk axis is undeclared (fail-closed default)"
      ],
      "note": "The band only moves a control UP to heightened; nothing moves a blocking control down to standard. The band is verifier-recomputed from recorded fields; any recorded band is ignored.",
      "rule_id": "SAMP-09"
    },
    "enum": [
      "standard",
      "heightened"
    ],
    "fail_closed_default": "heightened",
    "parameters_by_band": {
      "heightened": "95% confidence / 5% tolerable deviation / 0 expected deviations",
      "standard": "90% confidence / 10% tolerable deviation / 0 expected deviations"
    }
  },
  "seed_derivation": {
    "draw_index": "the first draw is #draw-1; each extended-testing draw increments (#draw-2, #draw-3, ...) = count of prior draws for the control plus one",
    "formula": "seed = parseInt(first 8 hex chars of sha256('<dossier_id>@<corpus_version>#<control_canonical_uri>#draw-<k>'), 16)",
    "no_wall_clock": true,
    "ordering": "population sorted by canonical item identifiers (byte order of the recorded identifier strings)",
    "prng": "mulberry32",
    "procedure": "seed -> mulberry32 -> Fisher-Yates shuffle of the ordered population -> take the first n items",
    "rule_id": "SAMP-15",
    "source": "ANNEX 6; the corpus AP-87 sampler discipline (fixed-identifier + corpus-version seed, seeded PRNG, no live RNG)"
  },
  "selection_methods": [
    {
      "cap": null,
      "effectiveness_eligible": true,
      "method": "full-population",
      "requirements": "every enumerated population item tested; satisfies CAP-05 by construction",
      "rule_id": "SAMP-11",
      "source": "ANNEX 5"
    },
    {
      "cap": null,
      "effectiveness_eligible": true,
      "method": "random",
      "requirements": "deterministic seeded draw per seed_derivation; verifier recomputes the selected set from the recorded enumeration and fails conformance on divergence",
      "rule_id": "SAMP-15",
      "source": "ANNEX 6"
    },
    {
      "cap": null,
      "effectiveness_eligible": true,
      "method": "systematic",
      "requirements": "declared canonical ordering key; interval k = floor(population/n); start = seed mod k (seed per seed_derivation); an undeclared ordering key, or one correlated with the control's failure modes, is treated as haphazard",
      "rule_id": "SAMP-16",
      "source": "ANNEX 6"
    },
    {
      "cap": "tested",
      "draft_decision": "D-A2-1",
      "effectiveness_eligible": false,
      "method": "haphazard",
      "requirements": "non-reproducible selection; rung <= tested (a selection a verifier cannot recompute supports no representativeness statement)",
      "rule_id": "SAMP-17",
      "source": "ANNEX 6; tightens CAP-07"
    },
    {
      "cap": "tested",
      "draft_decision": "D-A2-1",
      "effectiveness_eligible": false,
      "method": "judgmental-with-rationale",
      "requirements": "recorded rationale naming the selection criterion and why it was preferred over a seeded draw is mandatory (absent => CAP-07 also applies); rung <= tested even with the rationale recorded (purposive selection supports no representativeness statement)",
      "rule_id": "SAMP-17",
      "source": "ANNEX 6; SAMP-18; tightens CAP-07"
    },
    {
      "cap": "tested",
      "effectiveness_eligible": false,
      "method": "management-selected",
      "requirements": "selection by the assessed organization; rung <= tested (CAP-07)",
      "rule_id": "SAMP-17",
      "source": "CAP-07; ANNEX 6"
    }
  ],
  "spec": "acam/ACAM-SAMPLING.md",
  "verifier_checks": [
    {
      "check_id": "SAMP-V-01",
      "implements": [
        "SAMP-01",
        "SAMP-07"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-02",
      "implements": [
        "SAMP-02",
        "SAMP-06"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-03",
      "implements": [
        "SAMP-03",
        "SAMP-04",
        "SAMP-05"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-04",
      "implements": [
        "SAMP-08",
        "SAMP-09"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-05",
      "implements": [
        "SAMP-10",
        "SAMP-11"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-06",
      "implements": [
        "SAMP-12"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-07",
      "implements": [
        "SAMP-13"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-08",
      "implements": [
        "SAMP-15"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-09",
      "implements": [
        "SAMP-16"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-10",
      "implements": [
        "SAMP-14",
        "SAMP-17",
        "SAMP-18"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-11",
      "implements": [
        "SAMP-19"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-12",
      "implements": [
        "SAMP-20",
        "SAMP-21",
        "SAMP-23"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-13",
      "implements": [
        "SAMP-22"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-14",
      "implements": [
        "SAMP-24",
        "SAMP-25"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-15",
      "implements": [
        "SAMP-26",
        "SAMP-27",
        "SAMP-28"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-16",
      "implements": [
        "SAMP-29"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    },
    {
      "check_id": "SAMP-V-17",
      "implements": [
        "SAMP-30"
      ],
      "status": "specified-not-implemented (WS-B B4)"
    }
  ],
  "window_rules": [
    {
      "condition": "Operating evidence dated outside assessment_window (start, end; <= 12 months).",
      "consequence": "inadmissible for tested/effective; excluded before any rung computation; no override, no justification path, no counted-exception path. Sample items are drawn from the population as it existed within the window; an item whose occurrence date falls outside the window is not a population member.",
      "rule_id": "SAMP-24",
      "source": "CAP-09; SPEC 11.3 W1"
    },
    {
      "condition": "Design evidence predating window start by more than 90 days, or by 90 days or less without a recorded justification.",
      "consequence": "item inadmissible",
      "rule_id": "SAMP-25",
      "source": "CAP-10; SPEC 11.3 W2"
    }
  ]
}
