{"id":"assess-acme-2025q2","orgId":"org-acme-001","profileId":"prof-acme-cur-001","title":"Acme Q2 2025 Cybersecurity Assessment","status":"completed","assessor":"Jane Rivera, CISSP","scope":"All business units and IT assets in North America.","methodology":"Interviews, document review, and technical testing.","overallScore":2.2,"functionScores":[{"functionId":"GV","score":2.3,"tier":2,"findings":[{"subcategoryId":"GV.OC-01","score":3,"implementationState":"implemented","evidence":"Mission-aligned cybersecurity strategy document reviewed and signed by the board."},{"subcategoryId":"GV.OC-02","score":2,"implementationState":"partially_implemented","evidence":"Stakeholder register exists but has not been updated in 8 months."},{"subcategoryId":"GV.OC-03","score":2,"implementationState":"partially_implemented","evidence":"Legal/regulatory inventory exists; GDPR compliance gaps noted."}]},{"functionId":"ID","score":2.5,"tier":2,"findings":[{"subcategoryId":"ID.AM-01","score":3,"implementationState":"implemented","evidence":"CMDB covers 95% of hardware assets."},{"subcategoryId":"ID.AM-02","score":2,"implementationState":"partially_implemented","evidence":"Software inventory incomplete for shadow IT."}]},{"functionId":"PR","score":2.8,"tier":3,"findings":[{"subcategoryId":"PR.AA-01","score":3,"implementationState":"implemented","evidence":"Centralized IAM with MFA enforced for all privileged accounts."}]},{"functionId":"DE","score":2.0,"tier":2,"findings":[{"subcategoryId":"DE.CM-01","score":2,"implementationState":"partially_implemented","evidence":"Network monitoring covers 70% of segments; OT network gaps exist."}]},{"functionId":"RS","score":1.5,"tier":1,"findings":[{"subcategoryId":"RS.MA-01","score":1,"implementationState":"not_implemented","evidence":"Incident response plan drafted but never executed or tested."}]},{"functionId":"RC","score":1.2,"tier":1,"findings":[{"subcategoryId":"RC.RP-01","score":1,"implementationState":"not_implemented","evidence":"No formal recovery plan; backups exist but are untested."}]}],"completedAt":"2025-06-01T14:22:00Z","createdAt":"2025-05-01T09:00:00Z","updatedAt":"2025-06-01T14:22:00Z"}