# A-035

- **Artifact ID:** A-035
- **Status:** ACTIVE
- **Public record:** https://record.cybersecurityhq.com/assumptions#A-035
- **Machine-record SHA-256:** `0433775f5c766d9c2846cab0162f4ee40b3e9cdbaa153e1387d58108110ca124`

## Complete structured record

```json
{
  "id": "A-035",
  "statement": "The security stack is defended at least as well as the assets it protects, and deploying a security control does not materially enlarge the exploitable surface.",
  "status": "ACTIVE",
  "category": "Under Pressure",
  "ledger_references": [
    "2026-03 — CHQ-P-2026-011: Eight vectors across thirteen signals establish that tool presence is not evidence of functioning control and that the security tier can itself become the exploited surface. The assumption is directly under pressure at CONFIRMED evidence state.",
    "2026-07-24 — SIEM platform first-ever federal exploited-list entry (July 2026): A widely deployed SIEM platform received its first-ever CISA KEV listing through an unauthenticated flaw exploited within days of its patch. The security monitoring tier was the compromised surface, not the monitored tier. Prior endpoint-protection exploitation instances are additive to this pattern.",
    "2026-07-24 — Malware-analysis appliance unauthenticated command injection (July 2026): A malware-analysis appliance was confirmed exploited through unauthenticated command injection. The analysis tier deployed to detect malicious code became an attack surface accessible without authentication. These two instances — SIEM and malware-analysis appliance in one window — establish the class: the analysis and monitoring tier, not only the protected tier, carries exploitation risk."
  ],
  "evidence_count": 8,
  "last_updated": "2026-07-24",
  "related_positions": [
    "CHQ-P-2026-011"
  ]
}
```
