# CHQ-ED-2026-006

- **Artifact ID:** CHQ-ED-2026-006
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-006
- **Machine-record SHA-256:** `99a7e5386bbafa2e6fe7b4a7efbe5ac3f5295950d0907d44177ef0efcad624bc`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-006",
  "associated_position": "CHQ-P-2026-006 v1.0",
  "relationship": "original",
  "issuance_date": "2026-03-14",
  "evidence_freeze_time": "2026-03-14T00:00:00Z",
  "total_exhibits": 3,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "",
      "claim_text": "Disaster recovery appliances store authentication credentials in plaintext on systems that lack endpoint detection.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "Position primary signal SIG-018: architectural condition across independent product categories and vendors. CrowdStrike 2026 GTR: attackers exploit visibility gaps across identity, cloud, and virtual environments while avoiding monitored endpoints. Pattern recurs across independent vendors and independent disclosure timelines.",
      "evidence_class": "E2"
    },
    {
      "claim_id": "C-02",
      "position_section": "",
      "claim_text": "Privileged access management tools expose pre-authentication code paths reachable by network actors without credentials.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "Position supporting signal SIG-019: PAM tools exposing pre-auth code paths. IBM X-Force 2026: public-facing application exploitation as top initial access vector, up 44% YoY. CHQ-SC-2026-002 (Management Plane Concentration, RATIFIED): control surface concentration confirmed across PAM and adjacent tooling.",
      "evidence_class": "E2"
    },
    {
      "claim_id": "C-03",
      "position_section": "",
      "claim_text": "Browser engines execute extension-supplied logic with session-level access across all origins; identity providers authenticate autonomous agents using static shared secrets indistinguishable from the credentials those agents protect.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "Position supporting signals SIG-020 and SIG-021. CrowdStrike 2026: 82% of detections malware-free, reflecting adversary operation within authenticated sessions. CHQ-SC-2026-003 (Verification Collapse, RATIFIED): verification mechanisms temporally misaligned with integrity degradation rate.",
      "evidence_class": "E2"
    },
    {
      "claim_id": "C-04",
      "position_section": "",
      "claim_text": "Certificate authorities issue trust assertions while the validity and rotation of their own infrastructure certificates depend on the same lifecycle they govern.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "CA/Browser Forum Ballot SC-081 (April 2025): CAs are governed by the same certificate lifecycle they administer. DigiCert 2025: CAs subject to CA/B Forum Baseline Requirements including certificate validity constraints on their own infrastructure. CHQ-P-2026-007: certificate lifetime compression operates within the software trust chain it governs, not above it.",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-05",
      "position_section": "",
      "claim_text": "The condition recurs across independent product categories, independent vendors, independent threat actors, and independent disclosure timelines, confirming structural rather than episodic failure.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "IBM X-Force 2026: identity-based exploitation consistent across manufacturing, financial services, North America. Flashpoint 2026: 1,500% rise in AI-related illicit discussions signals industrialization of exploitation. CrowdStrike 2026: cross-domain pattern across identity, cloud, and endpoint confirms architectural condition, not vendor-specific failure.",
      "evidence_class": "E2"
    },
    {
      "claim_id": "C-06",
      "position_section": "",
      "claim_text": "Certificate lifecycle automation and short-lived cryptographic credentials narrow the dependency window but do not resolve the structural condition.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "CA/Browser Forum Ballot SC-081: 47-day certificate maximum by 2029 reduces compromise window, does not eliminate CA dependency on its own governed infrastructure. CSA 2026: transition from long-lived to ephemeral credentials reduces exposure window but does not resolve verification architecture dependency. CHQ-P-2026-007: compression does not alter hardware trust architecture.",
      "evidence_class": "E2"
    }
  ],
  "signals": [],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-001",
      "title": "Identity as Configuration, Not Evidence",
      "temporal_tag": "HISTORICAL 1995–2022"
    },
    {
      "id": "CHQ-EX-2026-003",
      "title": "Centralized Update Infrastructure as Execution Surface",
      "temporal_tag": "HISTORICAL 2000–2024"
    },
    {
      "id": "CHQ-EX-2026-004",
      "title": "Historical Cost Structure of Trust Signal Production",
      "temporal_tag": "HISTORICAL 2010–2022"
    }
  ],
  "notice": [
    "This docket records claim-to-source mappings for CHQ-P-2026-006 v1.0.",
    "Evidence classification: E1 = primary source (standards body ballot, CA policy documentation). E2 = inferential (behavioral evidence from institutional reporting, cross-vendor pattern analysis).",
    "This Position carries a downstream obligation: all CHQ artifacts issued after this Position referencing trust verification, trust anchors, or self-attesting systems must explicitly inherit this condition or defend a specific exception.",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "integrity_statement": [
    "This docket records claim-to-source mappings for CHQ-P-2026-006 v1.0.",
    "Evidence classification: E1 = primary source (standards body ballot, CA policy documentation). E2 = inferential (behavioral evidence from institutional reporting, cross-vendor pattern analysis).",
    "This Position carries a downstream obligation: all CHQ artifacts issued after this Position referencing trust verification, trust anchors, or self-attesting systems must explicitly inherit this condition or defend a specific exception.",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "59d9498097b8451bcbb05a1b90e26ffc9780d23d98c883a51ce3ccdda057c11b",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-006 Docket Hash",
      "scope": "the evidence record (claim-to-source mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-006 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
