# CHQ-ED-2026-004

- **Artifact ID:** CHQ-ED-2026-004
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-004
- **Machine-record SHA-256:** `10e1939977e65a961843d17ee6a69d222833366fecfb0af57de8627fa81f7dd0`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-004",
  "associated_position": "CHQ-P-2026-001 v1.0",
  "relationship": "original",
  "issuance_date": "2026-03-14",
  "evidence_freeze_time": "2026-03-14T00:00:00Z",
  "total_exhibits": 2,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "",
      "claim_text": "Vendor-operated credentials bypass employee controls while retaining equivalent or greater capacity for system impact.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "Marquis servicer breach (Q1 2026): attackers reached a processor serving 700+ financial institutions via unpatched SonicWall, cascading exposure across all client institutions with no direct vulnerability on their part. IBM X-Force 2026: supply chain incidents nearly fourfold in five years via trusted developer identities and SaaS integrations.",
      "evidence_class": "E2"
    },
    {
      "claim_id": "C-02",
      "position_section": "",
      "claim_text": "Regulatory practice converges on impact-based accountability regardless of access origin.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "SEC Reg S-P amendments (Dec 3, 2025 for large entities; June 3, 2026 for smaller): covered institutions remain responsible for customer notification within 30 days regardless of whether breach originated at a service provider. 8-K Item 1.05: materiality determination follows organizational impact, not attribution. SEC 2026 exam priorities explicitly name third-party vendor risk management.",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-03",
      "position_section": "",
      "claim_text": "Forensic and regulatory standards do not permit attribution delay as justification for disclosure delay.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "SEC cybersecurity disclosure rule: four-business-day 8-K clock runs from materiality determination, not from attribution completion. Reg S-P: 72-hour vendor notification to covered institution; institution bears customer notification responsibility irrespective of vendor fault. CBIZ Reg S-P analysis (2025): accountability obligation does not transfer to vendor.",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-04",
      "position_section": "",
      "claim_text": "Third-party access incidents are evaluated as internal incidents under active disclosure and governance frameworks.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "Drift/Salesforce OAuth chain (Q1 2026): Drift OAuth token compromise enabled access to Salesforce customer environments. IBM X-Force 2026: ‘compromise of a trusted third party can enable indirect access to customer environments in ways organizations had not fully prepared for.’ Impacted organizations bore disclosure obligations irrespective of Drift as origin.",
      "evidence_class": "E2"
    },
    {
      "claim_id": "C-05",
      "position_section": "",
      "claim_text": "Accountability posture is established at first detection, not after attribution.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "SEC 8-K Item 1.05: four-business-day clock begins at materiality determination, which can precede full attribution. Reg S-P: 30-day customer notification window is not paused pending vendor investigation. Morgan Lewis SEC enforcement roundup (2025): 2026 exam priorities emphasize incident response program implementation including third-party scenarios.",
      "evidence_class": "E1"
    }
  ],
  "signals": [],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-001",
      "title": "Identity as Configuration, Not Evidence",
      "temporal_tag": "HISTORICAL 1995–2022"
    },
    {
      "id": "CHQ-EX-2026-008",
      "title": "Marquis Servicer Breach: Cascade Across 700+ Financial Institutions",
      "temporal_tag": "OPERATIONAL 2025-08 to 2026"
    }
  ],
  "notice": [
    "This docket records claim-to-source mappings for CHQ-P-2026-001 v1.0.",
    "Evidence classification: E1 = primary source (regulatory text, SEC rule, statutory authority). E2 = inferential (incident patterns, vendor telemetry, institutional reporting).",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "integrity_statement": [
    "This docket records claim-to-source mappings for CHQ-P-2026-001 v1.0.",
    "Evidence classification: E1 = primary source (regulatory text, SEC rule, statutory authority). E2 = inferential (incident patterns, vendor telemetry, institutional reporting).",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "0b0e03282ef843662c18d2c3b28d1e597f0d7006e400cb735d262e8d0311954a",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-004 Docket Hash",
      "scope": "the evidence record (claim-to-source mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-001 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
