# Chain of Custody -- Evidence Package Provenance

**Package ID:** EP-2026-04-12-acme-cui-prod
**Generated:** 2026-04-12T00:00:00Z

> **SYNTHETIC SAMPLE** -- this is a reference deliverable, not a real assessment.
> Acme Precision Manufacturing does not exist. The git commit hash, CI run ID,
> and signing key fingerprint below are illustrative placeholders; a production
> engagement would record the real values at package-seal time.

---

## Statement of Automated Generation

This evidence package was generated by an automated compliance-as-code pipeline.
No manual editing occurred after generation. Every artifact is deterministically
produced from the inputs listed below. In a production engagement, the package
can be reproduced by re-running the pipeline at the same git commit; this sample
was not produced by re-running a live pipeline against a real AWS account, so the
pipeline identity fields below are illustrative rather than a real audit trail.

---

## Pipeline Identity

| Field | Value |
|---|---|
| Pipeline Version | 1.0.0 |
| Git Repository | grc-eng (private) |
| Git Commit | `[commit-hash-set-at-package-seal]` |
| Git Branch | `main` |
| CI/CD Platform | GitHub Actions |
| CI Run ID | `[CI-run-id-set-at-package-seal]` |
| CI Run URL | `[CI-run-URL-set-at-package-seal]` |
| Signing Key Fingerprint | `[GPG fingerprint set at package-seal]` |
| Signature File | `SHA256SUMS.sig` (GPG detached signature; production only -- omitted from this sample) |

---

## Tool Chain

Each artifact is produced by a specific tool. The table below documents which
tool generated which output, from which input.

### Stage 1: Scanning

| Tool | Version | Purpose | Input | Output |
|---|---|---|---|---|
| Prowler | 4.x | AWS security scanning against CMMC L2 compliance framework | AWS API (account 111222333444), `compliance.json` | `prowler-scan-2026-04-12.json.gz` |

### Stage 2: Transformation

| Tool | Version | Purpose | Input | Output |
|---|---|---|---|---|
| oscal-emitter | 0.1.0 | Prowler JSON to OSCAL AR transformation | `prowler-scan-2026-04-12.json.gz`, `compliance.json` | `assessment-results.json` |
| oscal-emitter | 0.1.0 | Component-definitions to SSP assembly | `component-definitions/*.json`, `assessment-results.json` | `system-security-plan.json` |
| oscal-emitter | 0.1.0 | Failing observations to POA&M generation | `assessment-results.json`, SPRS scoring table | `poam.json` |

### Stage 3: Verification

| Tool | Version | Purpose | Input | Output |
|---|---|---|---|---|
| OPA / Conftest | 0.68.0 | Policy-as-code plan-time verification | Terraform plan JSON, `*.rego` policies | Pass/fail gate (pipeline fails on deny) |
| Steampipe | 0.24.x | Live-state compliance queries | AWS API, `*.sql` queries | Query results fed to oscal-emitter |
| compliance-trestle | 4.0.1 | OSCAL schema validation | `system-security-plan.json`, `assessment-results.json`, `poam.json` | Validation pass/fail (pipeline fails on error) |

### Stage 4: Packaging

| Tool | Version | Purpose | Input | Output |
|---|---|---|---|---|
| sha256sum | (system) | Integrity hashing | All output files | `SHA256SUMS` |
| gpg | 2.4.x | Detached signature | `SHA256SUMS`, signing key | `SHA256SUMS.sig` (production; omitted from sample -- no production grc.engineering signing key is exposed to public samples) |

---

## Input Artifacts

| Input | Source | Integrity |
|---|---|---|
| `compliance.json` | `controls/cmmc-l2/compliance.json` (Prowler JSON fork per ADR-005) | Committed to git, tracked by commit hash |
| `component-definitions/*.json` | `controls/cmmc-l2/*/oscal/component-definition.json` | Committed to git, tracked by commit hash |
| Prowler scan data | Live scan of AWS account 111222333444 | Scan UUID in assessment-results metadata |
| NIST SP 800-171 Rev 2 catalog | `artifacts/registry/nist-800-171r2/` (pin pending -- see registry) | SHA256-pinned where available |

---

## Reproducibility

In a production engagement, the package is reproduced with:

```bash
git checkout [commit-hash-set-at-package-seal]
export AWS_PROFILE=<client-profile>
make evidence-package
sha256sum -c SHA256SUMS   # must match
```

The pipeline is deterministic given the same git commit and AWS account state.
Timestamp fields will differ on re-run, but all control mappings, component
definitions, and structural content will be identical. This sample was not
produced by running that command against a real AWS account -- there is no
`acme-cui-prod` AWS profile or account to check out and re-scan.

---

## Audit Trail

| Timestamp | Event | Actor |
|---|---|---|
| 2026-04-12T00:00:00Z | Pipeline triggered | GitHub Actions (schedule: daily 00:00 UTC) |
| 2026-04-12T00:02:15Z | Prowler scan started | prowler-scanner service account |
| 2026-04-12T00:14:42Z | Prowler scan completed | prowler-scanner service account |
| 2026-04-12T00:14:43Z | OSCAL transformation started | oscal-emitter |
| 2026-04-12T00:15:01Z | OSCAL validation passed | compliance-trestle |
| 2026-04-12T00:15:02Z | SHA256SUMS generated | sha256sum |
| 2026-04-12T00:15:03Z | Package published to artifact store | GitHub Actions |

---

## Limitations of this sample

- **All values are fabricated.** No real Acme Precision Manufacturing AWS
  account exists. AWS account `111222333444`, the Prowler scan output, and all
  resource ARNs are synthetic fixture data.
- **No GPG signature.** This sample does not ship a real `SHA256SUMS.sig`
  because there is no production grc.engineering signing key exposed to public
  samples. A real engagement would seal with a signed detached signature.
- **Git commit hash, CI run ID, and CI run URL are placeholders.** A production
  engagement would pin the actual values at package-seal time. This sample was
  not generated by an actual GitHub Actions run.
