---
document: MVAP-SPECIFICATION
version: 1.1
status: adopted
adopted_date: 2026-12-20
prior_version: mvap/MVAP-SPECIFICATION-v1.0.md
board_vote: 20/27
risk_assessment: mvap/ZERO-DAY-OPEN-SOURCE-RISK-ASSESSMENT.md
---

# MVAP Specification v1.1 — Adopted

Supersedes v1.0. Incorporates backlog completion, elevated Pillar 6, and **Pillar 7 — Open-Source & Zero-Day Diligence**.

---

## Backlog Items — COMPLETED

| Item | Control | Status | Evidence |
|------|---------|--------|----------|
| P4-03.1 | Ingest-path anomaly detection (pre-retrieval) | ✅ DEPLOYED | Hash + MIME + entropy gate on RAG ingest |
| P2-03.2 | QR/binary object extraction in DOCX/PDF | ✅ DEPLOYED | libreoffice headless + exiftool scrub pipeline |
| Pillar 6 | Firmware/GPU attestation | ✅ ELEVATED mandatory tier-1 | TPM attestation + driver CVE KEV sweep |
| Appendix A | OT AI Tier IEC 62443 | ✅ OPERATIONAL | $180K track; separate audit cycle |
| P4-06 RTO | Quarterly restore drill | ✅ PASSED | RTO 26h (improved from 48h) |

---

## Pillar 7 — Open-Source & Zero-Day Diligence (NEW)

**Vote:** 20/27 PASS

### Purpose

Evaluate OS and application-layer open-source components for zero-day exposure; assume AI accelerates exploit discovery and weaponization; compensate for **degraded federal security governance** per `mvap/ZERO-DAY-OPEN-SOURCE-RISK-ASSESSMENT.md`.

### Requirements

| ID | Control | Evidence Artifact |
|----|---------|-------------------|
| P7-01 | Daily CISA KEV cross-reference against AI stack SBOM + OS package manifest | KEV compliance dashboard export |
| P7-02 | Native code SAST (CodeQL/Semgrep) on compiled ML dependencies | CI gate pass log |
| P7-03 | Tier-1: fuzzing program (libFuzzer/AFL++) on custom parsers | Fuzz crash triage log (quarterly) |
| P7-04 | AI-assisted source audit with **mandatory human sign-off** — no autonomous deploy | Human review attestation per release |
| P7-05 | Historical zero-day regression tabletop (ATT&CK + CVE timeline) | Annual tabletop minutes |
| P7-06 | Open-source provenance: signed commits + Sigstore for internal AI forks | Provenance attestation chain |
| P7-07 | Classified-adjacent AI workloads: spill prevention, air-gapped embeddings, DCSA-aligned vendor review | NISP compliance checklist |
| P7-08 | Redundant threat intel — not CISA-only (ISAC + commercial + Five Eyes) | Intel source redundancy map |

### Government Risk Context (Mandatory Reading)

All tier-1 AI owners must acknowledge ongoing risks documented in:

- [CSA — CISA Leadership Vacuum (2026-04-24)](https://labs.cloudsecurityalliance.org/research/csa-research-note-cisa-leadership-governance-vacuum-20260424/)
- [GAO-26-107861 — 815 Classified Contractor Violations (2026-04-24)](https://www.gao.gov/products/gao-26-107861)
- [GCA — Salt Typhoon Across the Internet](https://globalcyberalliance.org/new-report-salt-typhoon-across-the-internet/)
- [CISA Advisory AA25-239A — Salt Typhoon](https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a)
- [Trend Micro — U.S. Public Sector Under Siege Q1 2026](https://www.trendmicro.com/en_us/research/26/d/us-public-sector-under-siege.html)
- [TechCrunch — Acting CISA chief uploaded FOUO docs to ChatGPT (2026-01-28)](https://techcrunch.com/2026/01/28/trumps-acting-cybersecurity-chief-uploaded-sensitive-government-docs-to-chatgpt/)
- [GAO-26-109159 — Water Sector Cybersecurity (2026-05-21)](https://www.gao.gov/products/gao-26-109159)

---

## Pillar 6 — Firmware & Sub-Application Layer (ELEVATED)

**Vote:** 17/27 — mandatory for tier-1 Critical systems (was advisory in v1.0)

| ID | Control |
|----|---------|
| P6-01 | GPU driver + CUDA runtime KEV sweep weekly |
| P6-02 | TPM/firmware attestation on inference nodes |
| P6-03 | Closed-source binary allowlist with Hex review attestation |

---

## L2 Pipeline Gates (Updated)

1. P1 registry check
2. P2 SAST + P2-03 poisoned-corpus ≥9/10
3. P3 SBOM + cosign verify
4. **P7-01 KEV sweep pass** (new)
5. P7-04 human sign-off on AI-generated security patches (new)

---

## Certification Status (2026-12-20)

| Component | Status |
|-----------|--------|
| MVAP L2 | ✅ Operational |
| MVAP v1.1 | ✅ Adopted 20/27 |
| Backlog | ✅ Complete |
| Pillar 7 | ✅ Adopted |
| Zero-Day Risk Assessment | ✅ Living document v2.0 (2027-03-20) |
| P7 Playbook | ✅ mvap/P7-IMPLEMENTATION-PLAYBOOK.md |
| P7-05 Tabletop | ✅ sessions/2027-03-20-p7-05-zero-day-tabletop.md |
| v1.2 Draft | 📝 mvap/MVAP-SPECIFICATION-v1.2-DRAFT.md (P7-09–P7-11) |