{
  "framework_id": "TCF",
  "framework_name": "Texas Cybersecurity Framework",
  "framework_short_name": "TCF",
  "owner": {
    "organization": "Texas Department of Information Resources",
    "abbreviation": "DIR",
    "url": "https://dir.texas.gov/information-security/security-policy-and-planning/texas-cybersecurity-framework"
  },
  "version": "2025-05",
  "frameworkmapper_dataset_version": "1.0.0",
  "publication_date": "2025-05-01",
  "ingestion_date": "2026-05-06",
  "source": {
    "primary_document_url": "https://dir.texas.gov/sites/default/files/2025-05/Texas%20Cybersecurity%20Framework%20Controls%20and%20Definitions_revised.pdf",
    "primary_document_title": "Texas Cybersecurity Framework (TCF) 42 Security Control Objectives and Definitions (May 2025 revision)",
    "companion_documents": [
      {
        "title": "DIR Security Control Standards Catalog v2.1",
        "url": "https://dir.texas.gov/sites/default/files/2023-06/Security%20Control%20Standards%20Catalog%202.1%20for%20Web%20-%20UPDATED%206.21.23.pdf",
        "purpose": "Prescriptive 800-53-derived control library that backs TCF maturity assessments."
      },
      {
        "title": "TEA K-12 Cybersecurity Initiative",
        "url": "https://tea.texas.gov/academics/learning-support-and-programs/technology-planning/k-12-cybersecurity-initiative",
        "purpose": "Operationalization of TCF for K-12 districts; defines TEA-funded controls and assessment workflow."
      }
    ]
  },
  "lineage": {
    "primary_basis": "NIST CSF v1.1 (legacy 5-function model: Identify, Protect, Detect, Respond, Recover)",
    "control_catalog_basis": "DIR Security Control Standards Catalog v2.1, derived from NIST SP 800-53 Rev. 5",
    "maturity_model_basis": "ISO/IEC 21827:2008 (SSE-CMM) with CMMI scale conversion"
  },
  "provenance": {
    "objective_definitions": "Verbatim from the DIR TCF Controls and Definitions document (May 2025 revision). Authoritative.",
    "maturity_scale_levels": "Names and definitions for levels 0-5 are sourced from DIR's framework, which inherits from CMMI and ISO/IEC 21827 (SSE-CMM). Authoritative.",
    "state_agency_target": "Set to 3.0 ('Well Defined') for every objective, consistent with DIR Security Control Standards Catalog v2.1 convention. Authoritative.",
    "k12_target": "FrameworkMapper-recommended interim targets per objective (mix of 2.0 / 2.5 / 3.0). Reflect realistic Texas ISD capacity given current TEA initiative scope. NOT a DIR or TEA published per-objective target. Districts targeting DIR-strict 3.0 across all 42 objectives should use the 'State agency target' mode in the assessment.",
    "nonprofit_target": "Derived as min(k12_target, 3.0). FrameworkMapper-set, not DIR/TEA published.",
    "per_objective_maturity_rubric": "For 38 of 42 objectives, the level 0-5 rubric descriptions are template-generated (the same six template strings with the objective name interpolated). For 4 objectives (TCF-PR-14 Access Control, TCF-PR-21 Spam Filtering, TCF-DE-02 Malware Protection, TCF-RC-01 Disaster Recovery), the level 3 description is hand-authored with K-12-specific guidance referencing TEA-funded controls (managed EDR, MFA on staff email, DMARC, immutable backups). The per-objective rubric text is FrameworkMapper interpretive content - DIR's published TCF document does not include per-objective level-by-level rubrics.",
    "ucpa_scoring": "Computed by FrameworkMapper's Universal Control Prioritization Algorithm. Inputs (effectiveness, breadth, resilience) are author-set per objective and validated against DBIR / MITRE ATT&CK observed K-12 incident patterns.",
    "crosswalks": "TCF-to-NIST-800-53-r5 mappings derived from the lineage of the DIR Security Control Standards Catalog. Other crosswalks (CSF 2.0, CIS Controls, CMMC, HIPAA) are FrameworkMapper-generated and pending validation in subsequent dataset versions."
  },
  "applicability": {
    "mandatory_for": [
      "Texas state agencies (per SB 820)",
      "Public universities and junior colleges",
      "Nonprofits accepting Texas state funding (since 2019)"
    ],
    "operationalized_for_k12_by": "Texas Education Agency (TEA) via the K-12 Cybersecurity Initiative, executed through DIR Managed Security Services (MSS)",
    "statutory_drivers": [
      {
        "citation": "Texas Government Code §2054 (DIR authority)",
        "description": "Establishes DIR's role in setting cybersecurity policy for state agencies."
      },
      {
        "citation": "SB 820 (86R)",
        "description": "Cybersecurity policy requirement for state agencies; TCF satisfies the assessment component."
      },
      {
        "citation": "Texas Education Code §32.1021 (HB 18, 88R)",
        "description": "Standards for permissible electronic devices and software applications in K-12. Parallel to but distinct from TCF."
      },
      {
        "citation": "TEA K-12 Cybersecurity Initiative (FY24-FY27)",
        "description": "$55M (FY24/25) + $42M (FY26/27) appropriations supporting EDR, MFA, DMARC, and TCF assessments for Texas school systems."
      }
    ]
  },
  "functions": [
    {
      "function_id": "IDENTIFY",
      "function_name": "Identify",
      "function_short_code": "ID",
      "description": "Establish the organizational understanding needed to manage cybersecurity risk to systems, assets, data, and capabilities.",
      "objective_count": 11
    },
    {
      "function_id": "PROTECT",
      "function_name": "Protect",
      "function_short_code": "PR",
      "description": "Develop and implement appropriate safeguards to ensure delivery of critical services.",
      "objective_count": 24
    },
    {
      "function_id": "DETECT",
      "function_name": "Detect",
      "function_short_code": "DE",
      "description": "Develop and implement appropriate activities to identify the occurrence of a cybersecurity event.",
      "objective_count": 4
    },
    {
      "function_id": "RESPOND",
      "function_name": "Respond",
      "function_short_code": "RS",
      "description": "Develop and implement appropriate activities to take action regarding a detected cybersecurity incident.",
      "objective_count": 2
    },
    {
      "function_id": "RECOVER",
      "function_name": "Recover",
      "function_short_code": "RC",
      "description": "Develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity incident.",
      "objective_count": 1
    }
  ],
  "maturity_scale": {
    "levels": [
      {
        "level": 0,
        "name": "Not Performed",
        "definition": "The control objective is not addressed by the organization in any meaningful way.",
        "cmmi_equivalent": "Incomplete",
        "iso_21827_equivalent": "Not Performed"
      },
      {
        "level": 1,
        "name": "Performed Informally",
        "definition": "The control is performed in an ad hoc, undocumented manner. Outcomes are inconsistent and depend on individual effort.",
        "cmmi_equivalent": "Initial",
        "iso_21827_equivalent": "Performed Informally"
      },
      {
        "level": 2,
        "name": "Planned",
        "definition": "The control is planned and tracked. Procedures may exist but are not consistently followed across the organization.",
        "cmmi_equivalent": "Managed",
        "iso_21827_equivalent": "Planned and Tracked"
      },
      {
        "level": 3,
        "name": "Well Defined",
        "definition": "The control is documented, standardized, and consistently performed across the organization. This is the DIR-recommended target maturity for most objectives.",
        "cmmi_equivalent": "Defined",
        "iso_21827_equivalent": "Well Defined"
      },
      {
        "level": 4,
        "name": "Quantitatively Controlled",
        "definition": "The control is measured with quantitative metrics, performance is predictable, and deviations are managed statistically.",
        "cmmi_equivalent": "Quantitatively Managed",
        "iso_21827_equivalent": "Quantitatively Controlled"
      },
      {
        "level": 5,
        "name": "Continuously Improving",
        "definition": "The control is continuously optimized through innovation, automation, and root-cause analysis. Performance improvements are sustained.",
        "cmmi_equivalent": "Optimizing",
        "iso_21827_equivalent": "Continuously Improving"
      }
    ],
    "default_target": 3,
    "scoring_methodology": "TEA's published TCF self-assessment workbook uses a percentage-of-organization-meeting-each-level approach across six columns (one per maturity level). Percentages are weighted, summed, and normalized to produce a single 0-5 maturity score per objective. The roadmap view identifies process and documentation gaps required to reach 3.0."
  },
  "objectives": [
    {
      "objective_id": "TCF-ID-01",
      "dir_objective_name": "Privacy and Confidentiality",
      "function_id": "IDENTIFY",
      "objective_name": "Privacy and Confidentiality",
      "definition": "Ensuring the appropriate security of retained information and approved sharing under defined conditions with required safeguards and assurance. Includes the requirements of HIPAA, Texas Business & Commerce Code, and agency defined privacy policies that include and expand upon regulatory and legal requirements for establishing contractual/legal agreements for appropriate exchange and protection.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "tcf_assessment"
        ],
        "hb18_intersection": true,
        "ferpa_intersection": true,
        "k12_notes": "Districts must reconcile FERPA, COPPA, HB 18 §32.1021, and Texas Business & Commerce Code in a single privacy posture."
      },
      "ucpa": {
        "effectiveness": 0.72,
        "breadth": 0.85,
        "resilience": 0.45,
        "env_tags": [
          "tx_k12",
          "tx_dir_mss"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:PT-1",
            "target_name": "Policy and Procedures (PII)",
            "relationship": "equivalent",
            "confidence": "high",
            "notes": "PT family added in Rev. 5 specifically for privacy."
          },
          {
            "target_id": "800-53:PT-2",
            "target_name": "Authority to Process PII",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PT-3",
            "target_name": "PII Processing Purposes",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PT-5",
            "target_name": "Privacy Notice",
            "relationship": "subset_of",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:PM-17",
            "target_name": "Protecting Controlled Unclassified Information on External Systems",
            "relationship": "informs",
            "confidence": "medium"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Privacy and Confidentiality is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Privacy and Confidentiality is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Privacy and Confidentiality is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Privacy and Confidentiality is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Privacy and Confidentiality is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Privacy and Confidentiality is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Board-approved privacy policy",
        "Privacy officer appointment letter",
        "Vendor data sharing agreement template",
        "Annual privacy training completion report"
      ],
      "tags": [
        "privacy",
        "ferpa",
        "hipaa",
        "vendor_management",
        "k12_critical"
      ]
    },
    {
      "objective_id": "TCF-ID-02",
      "dir_objective_name": "Data Classification",
      "function_id": "IDENTIFY",
      "objective_name": "Data Classification",
      "definition": "Data classification provides a framework for managing data assets and information resources based on utility to the organization, intrinsic financial value and impact of loss and other associated risks. To apply the appropriate levels of protection as required by state and federal law as well as proprietary, ethical, operational, and privacy considerations, data, whether electronic or printed, must be classified. The data owner should consult with the Information Security organization and legal counsel on the classification of data as Restricted, Confidential, Agency-Internal, or Public. Consistent use of data classification reinforces with users the expected level of protection of data assets in accordance with required security policies.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "DIR's four-tier scheme (Restricted/Confidential/Agency-Internal/Public) maps reasonably to K-12 data types. Most districts treat student records as Confidential or Restricted by default."
      },
      "ucpa": {
        "effectiveness": 0.61,
        "breadth": 0.74,
        "resilience": 0.42,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:RA-2",
            "target_name": "Security Categorization",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SC-16",
            "target_name": "Transmission of Security and Privacy Attributes",
            "relationship": "subset_of",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:MP-3",
            "target_name": "Media Marking",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Data Classification is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Data Classification is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Data Classification is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Data Classification is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Data Classification is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Data Classification is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Data classification policy",
        "Data inventory tagged by classification",
        "Data owner appointment records"
      ],
      "tags": [
        "data_classification",
        "ferpa",
        "governance"
      ]
    },
    {
      "objective_id": "TCF-ID-03",
      "dir_objective_name": "Critical Information Asset Inventory",
      "function_id": "IDENTIFY",
      "objective_name": "Critical Information Asset Inventory",
      "definition": "Identification and prioritization of all of the organization's information assets so that they are prioritized according to criticality to the business, so that protections can be applied commensurate with the assets importance.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "SIS, financial systems, and identity systems are typically the top three critical assets for a Texas ISD. Many districts under-inventory shadow SaaS used by individual teachers."
      },
      "ucpa": {
        "effectiveness": 0.78,
        "breadth": 0.91,
        "resilience": 0.55,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:CM-8",
            "target_name": "System Component Inventory",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PM-5",
            "target_name": "System Inventory",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:RA-9",
            "target_name": "Criticality Analysis",
            "relationship": "equivalent",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Critical Information Asset Inventory is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Critical Information Asset Inventory is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Critical Information Asset Inventory is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Critical Information Asset Inventory is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Critical Information Asset Inventory is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Critical Information Asset Inventory is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Asset inventory with criticality ratings",
        "Business impact analysis",
        "Asset owner assignments"
      ],
      "tags": [
        "asset_management",
        "inventory",
        "k12_foundational"
      ]
    },
    {
      "objective_id": "TCF-ID-04",
      "dir_objective_name": "Enterprise Security Policy, Standards and Guidelines",
      "function_id": "IDENTIFY",
      "objective_name": "Enterprise Security Policy, Standards and Guidelines",
      "definition": "Maintain the organization's security policy framework, standards, and guidelines. Defines the acceptable use policy for agency information resources. Contributes to the definition of enterprise standards and secure configuration standards to ensure alignment to security specifications and risk management requirements. There will be situations where the strict application of an information security standard would significantly impair the functionality of a service. The exception management process provides a method for evaluating the risks associated with non-compliant conditions and tracking the exception until expiration.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "tcf_assessment"
        ],
        "hb18_intersection": true,
        "ferpa_intersection": false,
        "k12_notes": "Board-adopted policy is a near-universal requirement. Many districts adopt TASB model policy CQB (Technology Resources / Acceptable Use) as their baseline."
      },
      "ucpa": {
        "effectiveness": 0.7,
        "breadth": 0.92,
        "resilience": 0.5,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:PM-1",
            "target_name": "Information Security Program Plan",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PL-1",
            "target_name": "Policy and Procedures (Planning)",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PL-4",
            "target_name": "Rules of Behavior",
            "relationship": "subset_of",
            "confidence": "high",
            "notes": "Acceptable use policy mapping."
          },
          {
            "target_id": "800-53:CM-6",
            "target_name": "Configuration Settings",
            "relationship": "informs",
            "confidence": "medium",
            "notes": "Secure configuration standards reference."
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Enterprise Security Policy, Standards and Guidelines is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Enterprise Security Policy, Standards and Guidelines is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Enterprise Security Policy, Standards and Guidelines is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Enterprise Security Policy, Standards and Guidelines is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Enterprise Security Policy, Standards and Guidelines is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Enterprise Security Policy, Standards and Guidelines is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Board-adopted security policy",
        "Acceptable use policy",
        "Exception management register"
      ],
      "tags": [
        "governance",
        "policy",
        "k12_foundational"
      ]
    },
    {
      "objective_id": "TCF-ID-05",
      "dir_objective_name": "Control Oversight and Safeguard Assurance",
      "function_id": "IDENTIFY",
      "objective_name": "Control Oversight and Safeguard Assurance",
      "definition": "Catalog the security activities that are required to provide the appropriate security of information and information resources throughout the Enterprise. Evaluate the control activities that have been implemented in terms of maturity, scope/breadth of implementation, effectiveness or associated deficiency to assure required protection levels as specified by security policy, regulatory/legal requirements, compliance mandates, or organizational risk thresholds. Ensure that control activities are performed as required and performed in a manner that is auditable and verifiable. Identify control activities that are not implemented or are not effective at achieving the defined control objectives. Oversee the implementation of required controls to ensure ongoing audit readiness and effective control implementations.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [
          "tcf_assessment"
        ],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "TCF self-assessment IS the primary control oversight mechanism for most districts. ESC technical assistance helps fill the gap between assessment and ongoing oversight."
      },
      "ucpa": {
        "effectiveness": 0.65,
        "breadth": 0.8,
        "resilience": 0.45,
        "env_tags": [
          "tx_k12",
          "esc_supported"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:CA-2",
            "target_name": "Control Assessments",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CA-7",
            "target_name": "Continuous Monitoring",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PM-14",
            "target_name": "Testing, Training, and Monitoring",
            "relationship": "subset_of",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:PM-31",
            "target_name": "Continuous Monitoring Strategy",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Control Oversight and Safeguard Assurance is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Control Oversight and Safeguard Assurance is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Control Oversight and Safeguard Assurance is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Control Oversight and Safeguard Assurance is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Control Oversight and Safeguard Assurance is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Control Oversight and Safeguard Assurance is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Control catalog",
        "Annual control effectiveness review",
        "Audit findings tracker"
      ],
      "tags": [
        "governance",
        "audit",
        "continuous_monitoring"
      ]
    },
    {
      "objective_id": "TCF-ID-06",
      "dir_objective_name": "Information Security Risk Management",
      "function_id": "IDENTIFY",
      "objective_name": "Information Security Risk Management",
      "definition": "The assessment and evaluation of risk within the information resources and technology to ensure that business operations are capable of delivering programs and services efficiently and effectively within acceptable tolerances potential negative outcomes.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "tcf_assessment"
        ],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "TEA-funded TCF assessment serves as the de facto annual risk assessment for most districts. Larger districts should supplement with internal risk register."
      },
      "ucpa": {
        "effectiveness": 0.74,
        "breadth": 0.85,
        "resilience": 0.55,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:RA-3",
            "target_name": "Risk Assessment",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PM-9",
            "target_name": "Risk Management Strategy",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PM-28",
            "target_name": "Risk Framing",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Information Security Risk Management is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Information Security Risk Management is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Information Security Risk Management is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Information Security Risk Management is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Information Security Risk Management is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Information Security Risk Management is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Risk register",
        "Annual risk assessment report (TCF or equivalent)",
        "Risk treatment plans"
      ],
      "tags": [
        "risk_management",
        "governance",
        "tea_aligned"
      ]
    },
    {
      "objective_id": "TCF-ID-07",
      "dir_objective_name": "Security Oversight and Governance",
      "function_id": "IDENTIFY",
      "objective_name": "Security Oversight and Governance",
      "definition": "The set of responsibilities and practices exercised by the board and executive management with the goal of providing strategic direction, ensuring that objectives are achieved, ascertaining that risks are managed appropriately and verifying that the enterprise's resources are used responsibly.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "Superintendent and board are the de facto oversight body in most ISDs. CTO/CIO typically serves as security executive sponsor."
      },
      "ucpa": {
        "effectiveness": 0.62,
        "breadth": 0.84,
        "resilience": 0.48,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:PM-1",
            "target_name": "Information Security Program Plan",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PM-2",
            "target_name": "Information Security Program Leadership Role",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PM-29",
            "target_name": "Risk Management Program Leadership Roles",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Security Oversight and Governance is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Security Oversight and Governance is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Security Oversight and Governance is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Security Oversight and Governance is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Security Oversight and Governance is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Security Oversight and Governance is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Security steering committee charter",
        "Board cybersecurity report cadence",
        "Executive security briefing materials"
      ],
      "tags": [
        "governance",
        "leadership",
        "board_oversight"
      ]
    },
    {
      "objective_id": "TCF-ID-08",
      "dir_objective_name": "Security Compliance and Regulatory Requirements Management",
      "function_id": "IDENTIFY",
      "objective_name": "Security Compliance and Regulatory Requirements Management",
      "definition": "Monitor the legislative and industry landscape to ensure security policy is updated in consideration of changes that are pertinent or applicable to the organization. Facilitate any validation audits, assessments or reporting that is necessary to assure compliance to applicable laws, regulations, or requirements. Includes the HIPAA Privacy Office(r), IRS Safeguard Reviews, and responses to third party inquiries into the security of the organization.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "tcf_assessment"
        ],
        "hb18_intersection": true,
        "ferpa_intersection": true,
        "k12_notes": "K-12 compliance landscape: FERPA, COPPA, CIPA, HB 18, Texas Business & Commerce Code §521, plus federal grant conditions. Districts taking E-Rate or TEA grants face additional scrutiny."
      },
      "ucpa": {
        "effectiveness": 0.71,
        "breadth": 0.88,
        "resilience": 0.5,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:PM-8",
            "target_name": "Critical Infrastructure Plan",
            "relationship": "informs",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:PM-10",
            "target_name": "Authorization Process",
            "relationship": "subset_of",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:CA-2",
            "target_name": "Control Assessments",
            "relationship": "informs",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:AR-2",
            "target_name": "Privacy Impact and Risk Assessment",
            "relationship": "subset_of",
            "confidence": "high",
            "notes": "HIPAA Privacy Officer reference in TCF definition."
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Security Compliance and Regulatory Requirements Management is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Security Compliance and Regulatory Requirements Management is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Security Compliance and Regulatory Requirements Management is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Security Compliance and Regulatory Requirements Management is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Security Compliance and Regulatory Requirements Management is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Security Compliance and Regulatory Requirements Management is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Compliance register (laws/regs applicable to district)",
        "Audit/assessment results archive",
        "Third-party inquiry response log"
      ],
      "tags": [
        "compliance",
        "regulatory",
        "ferpa",
        "cipa",
        "hb18"
      ]
    },
    {
      "objective_id": "TCF-ID-09",
      "dir_objective_name": "Cloud Usage and Security",
      "function_id": "IDENTIFY",
      "objective_name": "Cloud Usage and Security",
      "definition": "The assessment and evaluation of risk with the use of \"cloud\" technologies including Software as a Service (SAAS), Platform as a Service (PAAS), and Information as a Service (IAAS), to ensure that business operations are capable of delivering programs and services efficiently and effectively within acceptable tolerances potential negative outcomes.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": true,
        "ferpa_intersection": true,
        "k12_notes": "K-12 is heavily cloud-dependent (Google Workspace / M365, plus dozens of EdTech SaaS apps per district). HB 18 device/software standards directly intersect this objective. Gap objective in most existing frameworks."
      },
      "ucpa": {
        "effectiveness": 0.79,
        "breadth": 0.93,
        "resilience": 0.62,
        "env_tags": [
          "tx_k12",
          "cloud_first"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SA-9",
            "target_name": "External System Services",
            "relationship": "equivalent",
            "confidence": "high",
            "notes": "Primary anchor for cloud (SaaS/PaaS/IaaS) governance."
          },
          {
            "target_id": "800-53:CA-3",
            "target_name": "Information Exchange",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-20",
            "target_name": "Use of External Systems",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SR-3",
            "target_name": "Supply Chain Controls and Processes",
            "relationship": "informs",
            "confidence": "medium"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Cloud Usage and Security is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Cloud Usage and Security is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Cloud Usage and Security is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Cloud Usage and Security is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Cloud Usage and Security is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Cloud Usage and Security is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "SaaS inventory",
        "Cloud security policy",
        "Vendor risk assessments for cloud services",
        "DPAs/SCCs for cloud providers"
      ],
      "tags": [
        "cloud",
        "saas",
        "vendor_risk",
        "k12_critical",
        "gap_objective"
      ]
    },
    {
      "objective_id": "TCF-ID-10",
      "dir_objective_name": "Security Assessment and Authorization / Technology Risk Assessments",
      "function_id": "IDENTIFY",
      "objective_name": "Security Assessment and Authorization / Technology Risk Assessments",
      "definition": "Evaluate systems and applications in terms of design and architecture in conjunction with existing or available controls to ensure that current and anticipated threats are mitigated within acceptable risk tolerances. Includes an analysis of in-place systems periodically or when significant change occurs as well as the analysis of the introduction of new technology systems.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [
          "tcf_assessment"
        ],
        "hb18_intersection": true,
        "ferpa_intersection": false,
        "k12_notes": "Most districts perform informal architecture review. HB 18 introduces a formal review requirement for new software/applications used by students."
      },
      "ucpa": {
        "effectiveness": 0.68,
        "breadth": 0.78,
        "resilience": 0.5,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:CA-2",
            "target_name": "Control Assessments",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CA-6",
            "target_name": "Authorization",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CA-8",
            "target_name": "Penetration Testing",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:RA-3",
            "target_name": "Risk Assessment",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Security Assessment and Authorization / Technology Risk Assessments is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Security Assessment and Authorization / Technology Risk Assessments is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Security Assessment and Authorization / Technology Risk Assessments is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Security Assessment and Authorization / Technology Risk Assessments is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Security Assessment and Authorization / Technology Risk Assessments is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Security Assessment and Authorization / Technology Risk Assessments is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "New system review checklist",
        "Risk acceptance documents",
        "Architecture review records"
      ],
      "tags": [
        "assessment",
        "authorization",
        "architecture_review",
        "hb18_aligned"
      ]
    },
    {
      "objective_id": "TCF-ID-11",
      "dir_objective_name": "External Vendors and Third Party Providers",
      "function_id": "IDENTIFY",
      "objective_name": "External Vendors and Third Party Providers",
      "definition": "Evaluation of third party providers and external vendors to ensure security requirements are met for information and information resources that will be transmitted, processed, stored, or managed by external entities. Includes contract review as well as the development of service level agreements and requirements.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": true,
        "ferpa_intersection": true,
        "k12_notes": "Third-party EdTech vendors are the dominant data-handling risk in K-12. CoSN's K12CVAT and HECVAT-Lite are common assessment instruments. HB 18 vendor self-attestation creates a baseline."
      },
      "ucpa": {
        "effectiveness": 0.81,
        "breadth": 0.91,
        "resilience": 0.58,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SA-9",
            "target_name": "External System Services",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SA-4",
            "target_name": "Acquisition Process",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SR-2",
            "target_name": "Supply Chain Risk Management Plan",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SR-5",
            "target_name": "Acquisition Strategies, Tools, and Methods",
            "relationship": "subset_of",
            "confidence": "medium"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "External Vendors and Third Party Providers is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "External Vendors and Third Party Providers is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "External Vendors and Third Party Providers is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "External Vendors and Third Party Providers is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "External Vendors and Third Party Providers is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "External Vendors and Third Party Providers is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Vendor inventory with risk tiers",
        "Vendor security questionnaires (K12CVAT/HECVAT)",
        "Executed DPAs/DSAs",
        "Vendor monitoring records"
      ],
      "tags": [
        "vendor_management",
        "third_party_risk",
        "ferpa",
        "hb18",
        "k12_critical"
      ]
    },
    {
      "objective_id": "TCF-PR-01",
      "dir_objective_name": "Enterprise Architecture, Roadmap and Emerging Technology",
      "function_id": "PROTECT",
      "objective_name": "Enterprise Architecture, Roadmap and Emerging Technology",
      "definition": "An enterprise information security architecture that is aligned with Federal, State, Local and agency data security and privacy requirements. The integration of information security requirements and associated security controls into the information security architecture helps to ensure that security considerations are addressed early in the system development life cycle and are directly and explicitly related to mission/business processes. Using a roadmap and emerging technology evaluation process, the Information Security Program will stay abreast of the continued evolution of security solutions, processes, and technology to identify continuous, ongoing ways to deliver technology and information securely.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "Few K-12 districts have formal security architecture documents. ESC partnerships and TEA roadmap guidance partially fill this gap."
      },
      "ucpa": {
        "effectiveness": 0.55,
        "breadth": 0.72,
        "resilience": 0.4,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:PL-8",
            "target_name": "Security and Privacy Architectures",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SA-3",
            "target_name": "System Development Life Cycle",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PM-7",
            "target_name": "Enterprise Architecture",
            "relationship": "equivalent",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Enterprise Architecture, Roadmap and Emerging Technology is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Enterprise Architecture, Roadmap and Emerging Technology is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Enterprise Architecture, Roadmap and Emerging Technology is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Enterprise Architecture, Roadmap and Emerging Technology is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Enterprise Architecture, Roadmap and Emerging Technology is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Enterprise Architecture, Roadmap and Emerging Technology is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Security architecture document",
        "Multi-year security roadmap",
        "Emerging tech evaluation process"
      ],
      "tags": [
        "architecture",
        "strategy",
        "roadmap"
      ]
    },
    {
      "objective_id": "TCF-PR-02",
      "dir_objective_name": "Secure System Services, Acquisition and Development",
      "function_id": "PROTECT",
      "objective_name": "Secure System Services, Acquisition and Development",
      "definition": "Ensure that the development and implementation of new systems meets the requirements necessary to assure the security of information and resources.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [],
        "hb18_intersection": true,
        "ferpa_intersection": false,
        "k12_notes": "Districts generally do not develop custom software. This objective primarily applies to procurement and integration of acquired systems. HB 18 procurement-time security review applies."
      },
      "ucpa": {
        "effectiveness": 0.6,
        "breadth": 0.7,
        "resilience": 0.42,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SA-3",
            "target_name": "System Development Life Cycle",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SA-4",
            "target_name": "Acquisition Process",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SA-8",
            "target_name": "Security and Privacy Engineering Principles",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SA-11",
            "target_name": "Developer Testing and Evaluation",
            "relationship": "subset_of",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:SA-15",
            "target_name": "Development Process, Standards, and Tools",
            "relationship": "subset_of",
            "confidence": "medium"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Secure System Services, Acquisition and Development is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Secure System Services, Acquisition and Development is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Secure System Services, Acquisition and Development is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Secure System Services, Acquisition and Development is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Secure System Services, Acquisition and Development is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Secure System Services, Acquisition and Development is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Secure procurement checklist",
        "Pre-deployment security review records",
        "SLA security clauses"
      ],
      "tags": [
        "sdlc",
        "procurement",
        "secure_development",
        "hb18_aligned"
      ]
    },
    {
      "objective_id": "TCF-PR-03",
      "dir_objective_name": "Security Awareness and Training",
      "function_id": "PROTECT",
      "objective_name": "Security Awareness and Training",
      "definition": "Define, prepare, deliver, and facilitate an ongoing awareness campaign utilizing a wide variety of mediums and delivery mechanisms to effectively and constantly educate the organization on security related information, threats, and technology risks.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "Phishing-driven incidents are the dominant K-12 attack vector. Annual training plus simulated phishing is the de facto baseline. KnowBe4 and Proofpoint are common K-12 platforms."
      },
      "ucpa": {
        "effectiveness": 0.83,
        "breadth": 0.94,
        "resilience": 0.5,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:AT-1",
            "target_name": "Policy and Procedures (Awareness/Training)",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AT-2",
            "target_name": "Literacy Training and Awareness",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AT-3",
            "target_name": "Role-Based Training",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AT-4",
            "target_name": "Training Records",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Security Awareness and Training is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Security Awareness and Training is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Security Awareness and Training is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Security Awareness and Training is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Security Awareness and Training is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Security Awareness and Training is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Annual training curriculum",
        "Completion tracking records",
        "Phishing simulation results",
        "Targeted training for high-risk roles"
      ],
      "tags": [
        "training",
        "awareness",
        "phishing",
        "k12_critical"
      ]
    },
    {
      "objective_id": "TCF-PR-04",
      "dir_objective_name": "Privacy Awareness and Training",
      "function_id": "PROTECT",
      "objective_name": "Privacy Awareness and Training",
      "definition": "Define, prepare, deliver, and facilitate an ongoing awareness campaign utilizing a wide variety of mediums and delivery mechanisms to effectively and constantly educate the organization on privacy requirements and information related to the protection of privacy risks and protections.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": true,
        "ferpa_intersection": true,
        "k12_notes": "FERPA training is typically annual and required for all staff with student data access. HB 18 introduces additional training expectations for staff approving software for student use. Gap objective."
      },
      "ucpa": {
        "effectiveness": 0.66,
        "breadth": 0.78,
        "resilience": 0.4,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:AT-3",
            "target_name": "Role-Based Training",
            "relationship": "subset_of",
            "confidence": "high",
            "notes": "Privacy-specific role-based training."
          },
          {
            "target_id": "800-53:PT-3",
            "target_name": "PII Processing Purposes",
            "relationship": "informs",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:AR-5",
            "target_name": "Privacy Awareness and Training",
            "relationship": "equivalent",
            "confidence": "high",
            "notes": "AR-5 from Appendix J of legacy 800-53 R4 Privacy Appendix; conceptually preserved in R5."
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Privacy Awareness and Training is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Privacy Awareness and Training is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Privacy Awareness and Training is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Privacy Awareness and Training is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Privacy Awareness and Training is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Privacy Awareness and Training is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "FERPA training curriculum",
        "Privacy training completion records",
        "Role-based privacy training (counselors, registrars)"
      ],
      "tags": [
        "privacy_training",
        "ferpa",
        "hb18",
        "gap_objective"
      ]
    },
    {
      "objective_id": "TCF-PR-05",
      "dir_objective_name": "Cryptography",
      "function_id": "PROTECT",
      "objective_name": "Cryptography",
      "definition": "Establish the rules and administrative guidelines governing the use of cryptography and key management in order to ensure that data is not disclosed or made inaccessible due to an inability to decrypt.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "TLS for data-in-transit is universal; data-at-rest encryption varies. Cloud providers handle most encryption transparently for districts."
      },
      "ucpa": {
        "effectiveness": 0.69,
        "breadth": 0.74,
        "resilience": 0.66,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SC-12",
            "target_name": "Cryptographic Key Establishment and Management",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SC-13",
            "target_name": "Cryptographic Protection",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SC-17",
            "target_name": "Public Key Infrastructure Certificates",
            "relationship": "subset_of",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:SC-28",
            "target_name": "Protection of Information at Rest",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Cryptography is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Cryptography is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Cryptography is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Cryptography is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Cryptography is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Cryptography is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Cryptography policy",
        "TLS configuration baselines",
        "Disk/database encryption attestations"
      ],
      "tags": [
        "cryptography",
        "encryption",
        "key_management"
      ]
    },
    {
      "objective_id": "TCF-PR-06",
      "dir_objective_name": "Secure Configuration Management",
      "function_id": "PROTECT",
      "objective_name": "Secure Configuration Management",
      "definition": "Ensure that baseline configurations and inventories of information systems (including hardware, software, firmware, and documentation) are established and maintained throughout the respective system development life cycles. Establishes and enforces security configuration settings for information technology products employed in information systems. Ensures all systems are operating under configurations that have been agreed upon according to organizational risk management.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "CIS Benchmarks are the typical baseline reference. Intune/Jamf MDM enforce configuration on managed devices."
      },
      "ucpa": {
        "effectiveness": 0.81,
        "breadth": 0.86,
        "resilience": 0.55,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:CM-2",
            "target_name": "Baseline Configuration",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CM-6",
            "target_name": "Configuration Settings",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CM-7",
            "target_name": "Least Functionality",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CM-8",
            "target_name": "System Component Inventory",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Secure Configuration Management is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Secure Configuration Management is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Secure Configuration Management is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Secure Configuration Management is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Secure Configuration Management is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Secure Configuration Management is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Configuration baselines (CIS or equivalent)",
        "MDM/GPO configuration exports",
        "Configuration drift reports"
      ],
      "tags": [
        "configuration_management",
        "hardening",
        "cis_benchmarks"
      ]
    },
    {
      "objective_id": "TCF-PR-07",
      "dir_objective_name": "Change Management",
      "function_id": "PROTECT",
      "objective_name": "Change Management",
      "definition": "Establishes a set of rules and administrative guidelines to manage changes in a rational and predictable manner. In addition, it provides for the necessary documentation of any changes made so as to reduce any possible negative impact to the Users of IR systems. Changes include, but are not limited to implementation of new functionality, interruption of service, repair of existing functionality, and the removal of existing functionality.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "Most districts run informal change processes. Larger ISDs adopt ITIL-lite change advisory boards."
      },
      "ucpa": {
        "effectiveness": 0.62,
        "breadth": 0.74,
        "resilience": 0.55,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:CM-3",
            "target_name": "Configuration Change Control",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CM-4",
            "target_name": "Impact Analyses",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CM-5",
            "target_name": "Access Restrictions for Change",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Change Management is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Change Management is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Change Management is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Change Management is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Change Management is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Change Management is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Change management policy",
        "Change ticket history",
        "CAB meeting minutes (if applicable)"
      ],
      "tags": [
        "change_management",
        "operations"
      ]
    },
    {
      "objective_id": "TCF-PR-08",
      "dir_objective_name": "Contingency Planning",
      "function_id": "PROTECT",
      "objective_name": "Contingency Planning",
      "definition": "Plans for emergency response, backup operations, and post-incident occurrence recovery for information systems are established, maintained and effectively implemented to ensure the availability of critical information resources and continuity of operations in emergency situations. Backing up data and applications is a business requirement. It enables the recovery of data and applications in the event of loss or damage (natural disasters, system disk and other systems failures, intentional or unintentional human acts, data entry errors, or systems operator errors).",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "Closely related to TCF-RC-01 (Disaster Recovery). Contingency Planning emphasizes the planning artifact; Disaster Recovery emphasizes the recovery execution."
      },
      "ucpa": {
        "effectiveness": 0.78,
        "breadth": 0.83,
        "resilience": 0.95,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:CP-2",
            "target_name": "Contingency Plan",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CP-4",
            "target_name": "Contingency Plan Testing",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CP-9",
            "target_name": "System Backup",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CP-10",
            "target_name": "System Recovery and Reconstitution",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Contingency Planning is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Contingency Planning is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Contingency Planning is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Contingency Planning is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Contingency Planning is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Contingency Planning is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Contingency plan document",
        "Backup architecture diagram",
        "Annual plan review records"
      ],
      "tags": [
        "contingency_planning",
        "backups",
        "ransomware_resilience"
      ]
    },
    {
      "objective_id": "TCF-PR-09",
      "dir_objective_name": "Media",
      "function_id": "PROTECT",
      "objective_name": "Media",
      "definition": "The protection of digital and non-digital information system media, the assurance that access to information on information system media is limited to authorized users, and requirements that information system media is sanitized or destroyed before disposal or release for reuse. The requirement that safeguards are in place to restrict access to Information system media which includes both digital media (e.g., systems, diskettes, magnetic tapes, external/removable hard drives, flash/thumb drives and other portable mass storage devices, compact disks, and digital video disks) and non-digital media (e.g., paper, microfilm). This standard applies to mobile computing and communications devices with information storage capability (e.g., notebook/laptop computers, personal digital assistants, cellular telephones, digital cameras, and audio recording devices) as well as data center systems and servers.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "Device-disposal sanitization (1:1 device refresh cycles, retired servers) is the most common operational pain point. Removable-media policies often unenforced."
      },
      "ucpa": {
        "effectiveness": 0.55,
        "breadth": 0.65,
        "resilience": 0.42,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:MP-2",
            "target_name": "Media Access",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:MP-4",
            "target_name": "Media Storage",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:MP-5",
            "target_name": "Media Transport",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:MP-6",
            "target_name": "Media Sanitization",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:MP-7",
            "target_name": "Media Use",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Media is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Media is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Media is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Media is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Media is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Media is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Media handling policy",
        "Sanitization records (NIST SP 800-88 alignment)",
        "Disposal vendor certifications"
      ],
      "tags": [
        "media_protection",
        "sanitization",
        "data_destruction"
      ]
    },
    {
      "objective_id": "TCF-PR-10",
      "dir_objective_name": "Physical and Environmental Protection",
      "function_id": "PROTECT",
      "objective_name": "Physical and Environmental Protection",
      "definition": "Assure that physical access to information systems, equipment, and the respective operating environments is limited to authorized individuals. Protect the physical locations and support infrastructure for information systems to ensure that supporting utilities are provided for to limit unplanned disruptions. Protect information systems against environmental hazards and provide appropriate environmental controls in facilities containing information systems.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "MDF/IDF closet security varies widely by district. Many older campuses lack proper environmental controls or access logging."
      },
      "ucpa": {
        "effectiveness": 0.68,
        "breadth": 0.71,
        "resilience": 0.61,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:PE-2",
            "target_name": "Physical Access Authorizations",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PE-3",
            "target_name": "Physical Access Control",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PE-12",
            "target_name": "Emergency Lighting",
            "relationship": "subset_of",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:PE-13",
            "target_name": "Fire Protection",
            "relationship": "subset_of",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:PE-14",
            "target_name": "Environmental Controls",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Physical and Environmental Protection is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Physical and Environmental Protection is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Physical and Environmental Protection is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Physical and Environmental Protection is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Physical and Environmental Protection is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Physical and Environmental Protection is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Server room access logs",
        "Environmental monitoring records (temp/humidity)",
        "UPS/generator test logs"
      ],
      "tags": [
        "physical_security",
        "environmental_controls"
      ]
    },
    {
      "objective_id": "TCF-PR-11",
      "dir_objective_name": "Personnel Security",
      "function_id": "PROTECT",
      "objective_name": "Personnel Security",
      "definition": "Ensuring that individuals responsible for agency information are identified and their responsibilities are clearly defined. Any individuals occupying positions of responsibility within the agency (including third-party service providers) are trustworthy and meet established security criteria for those positions. Ensuring that information resources are protected during and after personnel actions such as terminations and transfers. Employing formal sanctions for personnel failing to comply with security policies and procedures.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "Background checks are universal in K-12 (Texas SBOE/SBEC requirements). Offboarding access removal is the chronic weak point."
      },
      "ucpa": {
        "effectiveness": 0.72,
        "breadth": 0.85,
        "resilience": 0.58,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:PS-2",
            "target_name": "Position Risk Designation",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PS-3",
            "target_name": "Personnel Screening",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PS-4",
            "target_name": "Personnel Termination",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PS-5",
            "target_name": "Personnel Transfer",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PS-8",
            "target_name": "Personnel Sanctions",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Personnel Security is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Personnel Security is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Personnel Security is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Personnel Security is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Personnel Security is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Personnel Security is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Position risk designations",
        "Background check policy",
        "Offboarding checklist with access removal steps"
      ],
      "tags": [
        "personnel_security",
        "background_check",
        "offboarding"
      ]
    },
    {
      "objective_id": "TCF-PR-12",
      "dir_objective_name": "Third-Party Personnel Security",
      "function_id": "PROTECT",
      "objective_name": "Third-Party Personnel Security",
      "definition": "Requires all third party providers to comply with all security policies and standards. Third-party providers include, for example, service bureaus, contractors, and other organizations providing information system development, information technology services, outsourced applications, and network and security management. Establishes personnel security requirements including roles and responsibilities with limits on access requirements defined in accordance to least privileged and data minimization methodologies. Monitors providers for compliance.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "MSPs and contractor access management is often weaker than employee access. Texas Education Code §22.0834 requires criminal history reviews for school contractors with access to students."
      },
      "ucpa": {
        "effectiveness": 0.69,
        "breadth": 0.79,
        "resilience": 0.5,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:PS-7",
            "target_name": "External Personnel Security",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SA-9",
            "target_name": "External System Services",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SA-21",
            "target_name": "Developer Screening",
            "relationship": "subset_of",
            "confidence": "medium"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Third-Party Personnel Security is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Third-Party Personnel Security is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Third-Party Personnel Security is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Third-Party Personnel Security is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Third-Party Personnel Security is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Third-Party Personnel Security is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Contractor access agreements",
        "Vendor personnel screening attestations",
        "Contractor offboarding records"
      ],
      "tags": [
        "third_party",
        "contractor_security",
        "msp_management"
      ]
    },
    {
      "objective_id": "TCF-PR-13",
      "dir_objective_name": "System Configuration Hardening and Patch Management",
      "function_id": "PROTECT",
      "objective_name": "System Configuration Hardening and Patch Management",
      "definition": "Ensure that systems are installed and maintained in a manner that prevents unauthorized access, unauthorized use, and service disruptions by configuring operation systems and software with appropriate parameters. Includes the removal of default accounts/passwords, disablement of unnecessary protocols/ports/services, and the ongoing distribution and installation of service packs/patches.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "local_admin_restriction"
        ],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "TEA's local admin restriction guidance lives partially here. Patch management for student devices (1:1 fleets) is the dominant operational challenge."
      },
      "ucpa": {
        "effectiveness": 0.86,
        "breadth": 0.92,
        "resilience": 0.62,
        "env_tags": [
          "tx_k12",
          "local_admin_restricted"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:CM-6",
            "target_name": "Configuration Settings",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CM-7",
            "target_name": "Least Functionality",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SI-2",
            "target_name": "Flaw Remediation",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:RA-5",
            "target_name": "Vulnerability Monitoring and Scanning",
            "relationship": "informs",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "System Configuration Hardening and Patch Management is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "System Configuration Hardening and Patch Management is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "System Configuration Hardening and Patch Management is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "System Configuration Hardening and Patch Management is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "System Configuration Hardening and Patch Management is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "System Configuration Hardening and Patch Management is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Patching policy with SLAs",
        "Vulnerability scan results pre/post-patching",
        "Hardening baselines applied"
      ],
      "tags": [
        "hardening",
        "patch_management",
        "tea_aligned",
        "k12_critical"
      ]
    },
    {
      "objective_id": "TCF-PR-14",
      "dir_objective_name": "Access Control",
      "function_id": "PROTECT",
      "objective_name": "Access Control",
      "definition": "Processes used to ensure access to applications, servers, databases, and network devices in the environment is limited to authorized personnel. Access is to be limited to authorized users, processes acting on behalf of authorized users, or authorized devices. Authorized users are further limited to the types of transactions and functions that they are permitted to exercise. Session limits, lockout features for failed login attempts, account expirations and disabling unused accounts are controls that provide access control.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "mfa_staff_email",
          "local_admin_restriction"
        ],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "TEA's MFA-on-staff-email and local admin restriction live primarily under this objective. Highest-leverage Protect-function objective for K-12."
      },
      "ucpa": {
        "effectiveness": 0.91,
        "breadth": 0.94,
        "resilience": 0.62,
        "env_tags": [
          "tx_k12",
          "mfa_staff_email",
          "local_admin_restricted",
          "tea_funded_edr"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:AC-2",
            "target_name": "Account Management",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-3",
            "target_name": "Access Enforcement",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-6",
            "target_name": "Least Privilege",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-7",
            "target_name": "Unsuccessful Logon Attempts",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-11",
            "target_name": "Device Lock",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-12",
            "target_name": "Session Termination",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Access Control is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Access Control is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Access Control is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Access control is well-defined and consistently enforced. MFA on staff email, local admin restricted, periodic access reviews performed, session timeouts enforced.",
          "indicators": [
            "MFA on all staff email and admin systems",
            "Local admin removed from standard staff workstations",
            "Quarterly access reviews documented",
            "15-minute session timeout on sensitive systems"
          ]
        },
        "level_4": {
          "description": "Access Control is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Access Control is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "MFA enrollment report",
        "Privileged account inventory",
        "Quarterly access review records",
        "Local admin removal documentation",
        "Session timeout policy"
      ],
      "tags": [
        "access_control",
        "mfa",
        "privileged_access",
        "tea_aligned",
        "k12_critical"
      ]
    },
    {
      "objective_id": "TCF-PR-15",
      "dir_objective_name": "Account Management",
      "function_id": "PROTECT",
      "objective_name": "Account Management",
      "definition": "Account Management establishes the standards for the creation, monitoring, control, and removal of accounts. A request process for accounts that includes authorization, approval for access by data owners, and acknowledgement of the user of their responsibilities are controls that assure proper account management. Periodic reviews of access entitlements as well as prompt removal of access during role change or employment termination are also controls that are part of account management.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "Joiner/mover/leaver process integration with HR/SIS systems is the operational gold standard. Most districts have manual gaps especially around mid-year role changes."
      },
      "ucpa": {
        "effectiveness": 0.84,
        "breadth": 0.91,
        "resilience": 0.58,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:AC-2",
            "target_name": "Account Management",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-5",
            "target_name": "Separation of Duties",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-6(7)",
            "target_name": "Review of User Privileges",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Account Management is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Account Management is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Account Management is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Account Management is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Account Management is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Account Management is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Account provisioning workflow",
        "Periodic access review records",
        "Termination access removal SLA tracking"
      ],
      "tags": [
        "account_management",
        "joiner_mover_leaver",
        "k12_critical"
      ]
    },
    {
      "objective_id": "TCF-PR-16",
      "dir_objective_name": "Security Systems Management",
      "function_id": "PROTECT",
      "objective_name": "Security Systems Management",
      "definition": "The design, implementation, configuration, administration, maintenance, monitoring, and ongoing support of security systems used to enforce security policy and provide security services. Systems include firewalls, Intrusion Prevention Systems (IPS), Internet Proxy Servers, Security Information and Event Management (SIEM) systems, and other control enforcement or monitoring systems.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "edr_managed",
          "ndr_pilot"
        ],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "Texas K-12 districts under 50K enrollment receive TEA-funded EDR through DIR MSS. SIEM is typically a self-funded add-on for larger districts."
      },
      "ucpa": {
        "effectiveness": 0.78,
        "breadth": 0.85,
        "resilience": 0.65,
        "env_tags": [
          "tx_k12",
          "tea_funded_edr"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SI-4",
            "target_name": "System Monitoring",
            "relationship": "subset_of",
            "confidence": "high",
            "notes": "SIEM/IDS/IPS operations."
          },
          {
            "target_id": "800-53:SC-7",
            "target_name": "Boundary Protection",
            "relationship": "subset_of",
            "confidence": "high",
            "notes": "Firewall operations."
          },
          {
            "target_id": "800-53:AU-6",
            "target_name": "Audit Record Review, Analysis, and Reporting",
            "relationship": "informs",
            "confidence": "medium"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Security Systems Management is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Security Systems Management is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Security Systems Management is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Security Systems Management is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Security Systems Management is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Security Systems Management is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Security tool inventory",
        "SIEM/EDR/firewall configuration documentation",
        "Operational runbooks"
      ],
      "tags": [
        "security_operations",
        "siem",
        "firewall",
        "edr",
        "tea_aligned"
      ]
    },
    {
      "objective_id": "TCF-PR-17",
      "dir_objective_name": "Network Access and Perimeter Controls",
      "function_id": "PROTECT",
      "objective_name": "Network Access and Perimeter Controls",
      "definition": "Network equipment such as servers, workstations, routers, switches and printers should be installed in a manner that prevents unauthorized access while limiting services to only authorized users. A perimeter should be established to delineate internal systems and prevent unauthorized external parties from tampering, attempting access or connecting without approved remote access methods.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "Network segmentation between student/staff/IoT VLANs is best practice but inconsistent across Texas districts. NDR pilot would extend visibility."
      },
      "ucpa": {
        "effectiveness": 0.79,
        "breadth": 0.84,
        "resilience": 0.65,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SC-7",
            "target_name": "Boundary Protection",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-17",
            "target_name": "Remote Access",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-18",
            "target_name": "Wireless Access",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-19",
            "target_name": "Access Control for Mobile Devices",
            "relationship": "subset_of",
            "confidence": "medium"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Network Access and Perimeter Controls is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Network Access and Perimeter Controls is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Network Access and Perimeter Controls is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Network Access and Perimeter Controls is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Network Access and Perimeter Controls is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Network Access and Perimeter Controls is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Network architecture diagram",
        "VLAN segmentation documentation",
        "Firewall rule review records",
        "Remote access policy"
      ],
      "tags": [
        "network_security",
        "segmentation",
        "perimeter"
      ]
    },
    {
      "objective_id": "TCF-PR-18",
      "dir_objective_name": "Internet Content Filtering",
      "function_id": "PROTECT",
      "objective_name": "Internet Content Filtering",
      "definition": "The enforcement of controls used to block access to Internet websites based upon categories of content, application types and granular application functions, time of day or amount of utilization, or the dynamically updated reputation of the destination. Includes Bandwidth Preservation, Inappropriate Content blocking, and Malware and Cyber-Threat Prevention components.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": true,
        "ferpa_intersection": false,
        "k12_notes": "CIPA-mandated for E-Rate participants. Intersects HB 18 §32.1021. Off-network filtering for 1:1 devices is the modern challenge. Gap objective in existing FrameworkMapper frameworks."
      },
      "ucpa": {
        "effectiveness": 0.68,
        "breadth": 0.71,
        "resilience": 0.3,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SC-7",
            "target_name": "Boundary Protection",
            "relationship": "partial_overlap",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:AC-4",
            "target_name": "Information Flow Enforcement",
            "relationship": "partial_overlap",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:SI-3",
            "target_name": "Malicious Code Protection",
            "relationship": "partial_overlap",
            "confidence": "medium",
            "notes": "Web malware prevention component only."
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Internet Content Filtering is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Internet Content Filtering is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Internet Content Filtering is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Internet Content Filtering is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Internet Content Filtering is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Internet Content Filtering is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Filtering vendor configuration export",
        "CIPA compliance attestation",
        "Off-network filtering policy",
        "Monthly threat blocking report"
      ],
      "tags": [
        "network_security",
        "cipa",
        "k12_critical",
        "filtering",
        "gap_objective",
        "hb18_aligned"
      ]
    },
    {
      "objective_id": "TCF-PR-19",
      "dir_objective_name": "Data Loss Prevention",
      "function_id": "PROTECT",
      "objective_name": "Data Loss Prevention",
      "definition": "Solution designed to detect and prevent potential data breach incidents where sensitive may be disclosed to unauthorized personnel by malicious intent or inadvertent mistake. Detection of data at risk can be performed while in use at the endpoint, while in motion during transmission across the network, and while at rest on data storage devices.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2,
        "state_agency_target": 3,
        "nonprofit_target": 2,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "Full DLP is rare in K-12 due to cost and complexity. Many districts rely on Google Workspace / M365 native DLP for email and file sharing."
      },
      "ucpa": {
        "effectiveness": 0.65,
        "breadth": 0.72,
        "resilience": 0.45,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SC-7(10)",
            "target_name": "Prevent Exfiltration",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SI-4(18)",
            "target_name": "Analyze Traffic and Covert Exfiltration",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SC-8",
            "target_name": "Transmission Confidentiality and Integrity",
            "relationship": "informs",
            "confidence": "medium"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Data Loss Prevention is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Data Loss Prevention is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Data Loss Prevention is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Data Loss Prevention is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Data Loss Prevention is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Data Loss Prevention is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "DLP policy",
        "DLP rule configurations",
        "DLP alert/incident logs"
      ],
      "tags": [
        "dlp",
        "data_protection",
        "exfiltration_prevention"
      ]
    },
    {
      "objective_id": "TCF-PR-20",
      "dir_objective_name": "Identification and Authentication",
      "function_id": "PROTECT",
      "objective_name": "Identification and Authentication",
      "definition": "The verification of the claimed identity of users, processes, or devices as a prerequisite to permitting access. Verification can be performed by accepting a password, a Personal Identification Number (PIN), smart card, biometric, token, exchange of cryptographic keys, etc. Passwords are the most common authentication factor used in the identification process for users. Password standards establish the rules for the creation, length and complexity requirements, distribution, retention and periodic change as well as suspension or expiration of authenticators.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "mfa_staff_email"
        ],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "Closely linked to TCF-PR-14 (Access Control). Identity federation (SSO) reduces password sprawl. ClassLink and Clever common in K-12."
      },
      "ucpa": {
        "effectiveness": 0.88,
        "breadth": 0.93,
        "resilience": 0.6,
        "env_tags": [
          "tx_k12",
          "mfa_staff_email"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:IA-2",
            "target_name": "Identification and Authentication (Organizational Users)",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:IA-5",
            "target_name": "Authenticator Management",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:IA-8",
            "target_name": "Identification and Authentication (Non-Organizational Users)",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Identification and Authentication is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Identification and Authentication is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Identification and Authentication is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Identification and Authentication is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Identification and Authentication is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Identification and Authentication is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Authentication policy",
        "MFA coverage report",
        "SSO/IdP configuration",
        "Password policy enforcement records"
      ],
      "tags": [
        "authentication",
        "mfa",
        "sso",
        "tea_aligned",
        "k12_critical"
      ]
    },
    {
      "objective_id": "TCF-PR-21",
      "dir_objective_name": "Spam Filtering",
      "function_id": "PROTECT",
      "objective_name": "Spam Filtering",
      "definition": "As digital messaging (e-mail, cellular messaging, etc.) has become an integral part of the business process, its abuse has also grown. This abuse often is manifested as \"SPAM\" or \"junk\" messaging which has the potential to, beyond its annoying nature, slow-down and/or clog the infrastructure required to process electronic messages. In addition, \"SPAM\" is often used as a transmission vehicle in the migration of malicious code infections. To limit the effects of \"SPAM\", messages will be examined for content and filtered as required.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "dmarc_compliance"
        ],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "DMARC/DKIM/SPF compliance is one of TEA's four 'strongly encouraged' controls. Most districts use Google/Microsoft native filtering plus a secondary email security gateway. Gap objective."
      },
      "ucpa": {
        "effectiveness": 0.79,
        "breadth": 0.81,
        "resilience": 0.45,
        "env_tags": [
          "tx_k12",
          "dmarc_required"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SI-8",
            "target_name": "Spam Protection",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SC-44",
            "target_name": "Detonation Chambers",
            "relationship": "informs",
            "confidence": "medium",
            "notes": "Sandbox-based attachment analysis."
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Spam Filtering is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Spam Filtering is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Spam Filtering is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Spam filtering active. DMARC policy at p=quarantine or p=reject (TEA-aligned). SPF and DKIM properly configured. Filter effectiveness reviewed periodically.",
          "indicators": [
            "DMARC policy at p=quarantine or stricter",
            "SPF and DKIM aligned for all sending domains",
            "Email filtering platform deployed",
            "Periodic effectiveness review"
          ]
        },
        "level_4": {
          "description": "Spam Filtering is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Spam Filtering is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "DMARC policy at p=quarantine or p=reject",
        "SPF/DKIM configuration",
        "Email filtering metrics",
        "Phishing mail blocked counts"
      ],
      "tags": [
        "email_security",
        "spam",
        "dmarc",
        "tea_aligned",
        "gap_objective"
      ]
    },
    {
      "objective_id": "TCF-PR-22",
      "dir_objective_name": "Portable and Remote Computing",
      "function_id": "PROTECT",
      "objective_name": "Portable and Remote Computing",
      "definition": "Computing is no longer limited to traditional workstations. Mobile computing has introduced tablets, smartphones, handhelds and other computing devices designed to be portable and facilitate productivity for remote users. Traditional controls still apply in many areas, but additional considerations must be made for portable devices and the specific configuration and enforcement of controls will likely require special consideration.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": true,
        "ferpa_intersection": false,
        "k12_notes": "1:1 device programs make this objective central to K-12. MDM (Intune, Jamf, Mosyle) is universal for managed fleets. BYOD policies vary."
      },
      "ucpa": {
        "effectiveness": 0.74,
        "breadth": 0.81,
        "resilience": 0.55,
        "env_tags": [
          "tx_k12",
          "byod_environment"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:AC-19",
            "target_name": "Access Control for Mobile Devices",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AC-17",
            "target_name": "Remote Access",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:MP-7",
            "target_name": "Media Use",
            "relationship": "informs",
            "confidence": "medium"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Portable and Remote Computing is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Portable and Remote Computing is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Portable and Remote Computing is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Portable and Remote Computing is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Portable and Remote Computing is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Portable and Remote Computing is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Mobile device policy",
        "MDM enrollment reports",
        "Remote work security guidelines"
      ],
      "tags": [
        "mobile_devices",
        "1to1",
        "mdm",
        "byod"
      ]
    },
    {
      "objective_id": "TCF-PR-23",
      "dir_objective_name": "System Communications Protection",
      "function_id": "PROTECT",
      "objective_name": "System Communications Protection",
      "definition": "The control, monitoring, management and protection of communications and transmissions between information systems. Includes network architecture considerations, inventory of confidential and restricted data transmissions, permitted inbound and outbound Internet communications, permitted inbound and outbound extranet and intranet communications, as well as communications between agencies. Establishes the requirements for protections such as link encryption, secure file transmission protocols, retention of files on source and destination systems, integrity validation, and restrictions for access at all levels (i.e. user/process, system, and network).",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "TLS for web traffic is universal. SFTP/secure file exchange varies. Inter-agency data transfers (TEA, DIR, ESCs) typically use defined channels."
      },
      "ucpa": {
        "effectiveness": 0.68,
        "breadth": 0.78,
        "resilience": 0.55,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SC-7",
            "target_name": "Boundary Protection",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SC-8",
            "target_name": "Transmission Confidentiality and Integrity",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SC-23",
            "target_name": "Session Authenticity",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "System Communications Protection is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "System Communications Protection is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "System Communications Protection is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "System Communications Protection is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "System Communications Protection is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "System Communications Protection is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Communications protection policy",
        "TLS configuration scan reports",
        "Secure file exchange procedures"
      ],
      "tags": [
        "communications_security",
        "tls",
        "secure_transmission"
      ]
    },
    {
      "objective_id": "TCF-PR-24",
      "dir_objective_name": "Information Systems Currency",
      "function_id": "PROTECT",
      "objective_name": "Information Systems Currency",
      "definition": "Ensures that the necessary knowledge, skills, hardware, software, and supporting infrastructure are available at a reasonable cost to support information systems operations. Includes the monitoring and planning of future system developments that enable the organization to leverage modern technology and reduce technical debt.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2,
        "state_agency_target": 3,
        "nonprofit_target": 2,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "medium",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "Many Texas districts run end-of-life infrastructure due to budget constraints. This is a common Texas K-12 weak spot. Gap objective in existing FrameworkMapper frameworks."
      },
      "ucpa": {
        "effectiveness": 0.58,
        "breadth": 0.74,
        "resilience": 0.5,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SA-22",
            "target_name": "Unsupported System Components",
            "relationship": "equivalent",
            "confidence": "high",
            "notes": "Closest single-control analog; technical debt management."
          },
          {
            "target_id": "800-53:MA-6",
            "target_name": "Timely Maintenance",
            "relationship": "informs",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:PM-3",
            "target_name": "Information Security and Privacy Resources",
            "relationship": "informs",
            "confidence": "medium",
            "notes": "Resource adequacy for systems lifecycle."
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Information Systems Currency is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Information Systems Currency is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Information Systems Currency is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Information Systems Currency is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Information Systems Currency is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Information Systems Currency is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "IT asset lifecycle plan",
        "End-of-life inventory",
        "Technology refresh budget"
      ],
      "tags": [
        "technical_debt",
        "lifecycle",
        "modernization",
        "gap_objective"
      ]
    },
    {
      "objective_id": "TCF-DE-01",
      "dir_objective_name": "Vulnerability Assessment",
      "function_id": "DETECT",
      "objective_name": "Vulnerability Assessment",
      "definition": "Assessment and monitoring of vulnerability detection and remediation including patch management processes, configuration management, system, database and application security vulnerabilities. Test and evaluate security controls and security defenses to ensure that required security posture levels are met. Perform and/or facilitate ongoing and periodic penetration testing of security defenses. Evaluate results of various penetration tests to provide risk based prioritization of mitigation.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "Internal vuln scanning (Nessus/OpenVAS/Qualys) is variable in K-12. ESC partnerships and TEA-funded assessments help fill the gap. Penetration testing is rare without grant funding."
      },
      "ucpa": {
        "effectiveness": 0.81,
        "breadth": 0.84,
        "resilience": 0.55,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:RA-5",
            "target_name": "Vulnerability Monitoring and Scanning",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CA-8",
            "target_name": "Penetration Testing",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SI-2",
            "target_name": "Flaw Remediation",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Vulnerability Assessment is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Vulnerability Assessment is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Vulnerability Assessment is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Vulnerability Assessment is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Vulnerability Assessment is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Vulnerability Assessment is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Vulnerability scanning policy",
        "Periodic scan results with trend analysis",
        "Penetration test reports",
        "Remediation tracking"
      ],
      "tags": [
        "vulnerability_management",
        "scanning",
        "penetration_testing"
      ]
    },
    {
      "objective_id": "TCF-DE-02",
      "dir_objective_name": "Malware Protection",
      "function_id": "DETECT",
      "objective_name": "Malware Protection",
      "definition": "The prevention, detection and cleanup of Malicious Code (including virus, worm, Trojan, Spyware and other similar variants). Protection is accomplished at varying layers including at the host, at the network, or at the gateway perimeter. Protection mechanisms must be updated periodically and frequently to address evolving threats and monitored to provide manual intervention where required.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "edr_managed"
        ],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "TEA-funded managed EDR (SentinelOne or CrowdStrike via DIR MSS) directly satisfies most of this objective for eligible districts under 50K enrollment."
      },
      "ucpa": {
        "effectiveness": 0.92,
        "breadth": 0.91,
        "resilience": 0.78,
        "env_tags": [
          "tx_k12",
          "tea_funded_edr"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:SI-3",
            "target_name": "Malicious Code Protection",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SI-4",
            "target_name": "System Monitoring",
            "relationship": "subset_of",
            "confidence": "high",
            "notes": "EDR behavioral detection component."
          },
          {
            "target_id": "800-53:SI-8",
            "target_name": "Spam Protection",
            "relationship": "informs",
            "confidence": "medium"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Malware Protection is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Malware Protection is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Malware Protection is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "EDR or equivalent malware protection deployed across servers and endpoints. Definitions and behavioral models updated automatically. Alerts routed to defined responders.",
          "indicators": [
            "EDR coverage on 100% of staff endpoints and servers",
            "TEA-funded managed EDR enrolled (if eligible)",
            "Automated update mechanism",
            "Alert triage runbook exists"
          ]
        },
        "level_4": {
          "description": "Malware Protection is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Malware Protection is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "EDR coverage report",
        "EDR configuration",
        "Quarantine/incident logs",
        "TEA MSS service confirmation (if applicable)"
      ],
      "tags": [
        "malware_protection",
        "edr",
        "antivirus",
        "tea_aligned",
        "k12_critical"
      ]
    },
    {
      "objective_id": "TCF-DE-03",
      "dir_objective_name": "Security Monitoring and Event Analysis",
      "function_id": "DETECT",
      "objective_name": "Security Monitoring and Event Analysis",
      "definition": "Analysis of security events and alerts as detected by the array of security enforcement devices and log collection facilities implemented throughout the Enterprise environment. System level events include server operating system security and system logs. Application level events include web application logs, application access logs, and other application associated log events. Security monitoring and analysis includes alert configuration and generation, event correlation as well as defining and distributing periodic reports and event statistical analysis.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [
          "edr_managed",
          "ndr_pilot"
        ],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "TEA-funded managed EDR partially satisfies this for districts under 50K enrollment. NDR pilot (paused) would extend coverage. Larger districts and those with sensitive data should consider SIEM independent of TEA funding."
      },
      "ucpa": {
        "effectiveness": 0.86,
        "breadth": 0.79,
        "resilience": 0.71,
        "env_tags": [
          "tx_k12",
          "tea_funded_edr"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:AU-6",
            "target_name": "Audit Record Review, Analysis, and Reporting",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:SI-4",
            "target_name": "System Monitoring",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:IR-5",
            "target_name": "Incident Monitoring",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Security Monitoring and Event Analysis is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Security Monitoring and Event Analysis is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Security Monitoring and Event Analysis is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Security Monitoring and Event Analysis is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Security Monitoring and Event Analysis is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Security Monitoring and Event Analysis is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "EDR coverage report",
        "SIEM/log platform inventory",
        "Alert triage runbook",
        "MTTD trend report"
      ],
      "tags": [
        "detection",
        "siem",
        "edr",
        "tea_aligned",
        "k12_critical"
      ]
    },
    {
      "objective_id": "TCF-DE-04",
      "dir_objective_name": "Audit Logging and Accountability",
      "function_id": "DETECT",
      "objective_name": "Audit Logging and Accountability",
      "definition": "Processes, policies, and procedures that enable organizations to establish an accurate and verifiable record of system relevant actions whether manual or automated for investigatory and accountability purposes.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "Logging is often inconsistent across K-12 environments. Cloud platform logs (Google Workspace, M365) typically retained 6 months by default; longer retention requires upgraded licensing."
      },
      "ucpa": {
        "effectiveness": 0.74,
        "breadth": 0.85,
        "resilience": 0.61,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:AU-2",
            "target_name": "Event Logging",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AU-3",
            "target_name": "Content of Audit Records",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AU-9",
            "target_name": "Protection of Audit Information",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AU-11",
            "target_name": "Audit Record Retention",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:AU-12",
            "target_name": "Audit Record Generation",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Audit Logging and Accountability is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Audit Logging and Accountability is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Audit Logging and Accountability is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Audit Logging and Accountability is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Audit Logging and Accountability is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Audit Logging and Accountability is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Logging policy with retention requirements",
        "Log source inventory",
        "Log integrity controls"
      ],
      "tags": [
        "logging",
        "audit_trail",
        "accountability"
      ]
    },
    {
      "objective_id": "TCF-RS-01",
      "dir_objective_name": "Cyber-Security Incident Response",
      "function_id": "RESPOND",
      "objective_name": "Cyber-Security Incident Response",
      "definition": "Establishes an operational incident handling capability for information systems that includes adequate preparation, detection, analysis, containment, recovery, and response activities. The Incident Response program is used to track, document, and report incidents to appropriate officials and/or authorities.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "Districts must coordinate with TEA, local law enforcement, and (for student PII breaches) Texas Attorney General per Business & Commerce Code §521. Tabletop exercises strongly recommended pre-incident."
      },
      "ucpa": {
        "effectiveness": 0.74,
        "breadth": 0.88,
        "resilience": 0.95,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:IR-1",
            "target_name": "Policy and Procedures (IR)",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:IR-4",
            "target_name": "Incident Handling",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:IR-6",
            "target_name": "Incident Reporting",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:IR-7",
            "target_name": "Incident Response Assistance",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:IR-8",
            "target_name": "Incident Response Plan",
            "relationship": "subset_of",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Cyber-Security Incident Response is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Cyber-Security Incident Response is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Cyber-Security Incident Response is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Cyber-Security Incident Response is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Cyber-Security Incident Response is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Cyber-Security Incident Response is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Written incident response plan",
        "Tabletop exercise after-action report",
        "Scenario runbooks",
        "Notification template library",
        "Cyber insurance policy and carrier contacts"
      ],
      "tags": [
        "incident_response",
        "tabletop",
        "k12_critical",
        "reporting"
      ]
    },
    {
      "objective_id": "TCF-RS-02",
      "dir_objective_name": "Privacy Incident Response",
      "function_id": "RESPOND",
      "objective_name": "Privacy Incident Response",
      "definition": "Management of events, issues, inquiries, and incidents when detected or reported to include all phases from investigation through resolution. Responsible for notifying and escalating incidents to appropriate personnel and coordinating activities to ensure timely isolation and containment, impact analysis, and any resulting remediation / resolution requirements. Incidents include but may not be limited to privacy breach, loss, theft, unauthorized access, malware infections, and occurrences of negligence, human error, or malicious acts.",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 2.5,
        "state_agency_target": 3,
        "nonprofit_target": 2.5,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": true,
        "k12_notes": "Texas Business & Commerce Code §521 requires notification to affected individuals and the Texas AG within 60 days of breach discovery for breaches involving 250+ Texans. FERPA breach notification expectations also apply. Gap objective."
      },
      "ucpa": {
        "effectiveness": 0.71,
        "breadth": 0.79,
        "resilience": 0.84,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:IR-8(1)",
            "target_name": "Incident Response Plan | Breaches",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:PT-5",
            "target_name": "Privacy Notice",
            "relationship": "informs",
            "confidence": "medium"
          },
          {
            "target_id": "800-53:IR-6",
            "target_name": "Incident Reporting",
            "relationship": "subset_of",
            "confidence": "high",
            "notes": "Privacy-scoped reporting (TX Bus & Comm Code §521 notification)."
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Privacy Incident Response is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Privacy Incident Response is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Privacy Incident Response is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "Privacy Incident Response is well-defined, standardized, and consistently performed across the organization. This is the DIR-recommended target.",
          "indicators": [
            "Documented and approved procedures",
            "Consistent execution across the organization",
            "Evidence of routine performance",
            "Periodic review cadence established"
          ]
        },
        "level_4": {
          "description": "Privacy Incident Response is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Privacy Incident Response is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Privacy incident response procedures",
        "AG notification templates",
        "Affected-party notification templates",
        "Privacy incident log"
      ],
      "tags": [
        "privacy_incident",
        "breach_notification",
        "ferpa",
        "gap_objective"
      ]
    },
    {
      "objective_id": "TCF-RC-01",
      "dir_objective_name": "Disaster Recovery Procedures",
      "function_id": "RECOVER",
      "objective_name": "Disaster Recovery Procedures",
      "definition": "Managing the recovery of data and applications in the event of loss or damage (natural disasters, system disk and other systems failures, intentional or unintentional human acts, data entry errors, or systems operator errors).",
      "definition_source_verbatim": true,
      "maturity_targets": {
        "k12_target": 3,
        "state_agency_target": 3,
        "nonprofit_target": 3,
        "rationale": "DIR convention is 3.0 for state agencies. K-12 target adjusted for realistic district capacity given TEA initiative scope."
      },
      "k12_applicability": {
        "relevance": "high",
        "tea_initiative_alignment": [],
        "hb18_intersection": false,
        "ferpa_intersection": false,
        "k12_notes": "K-12 ransomware incidents in Texas have repeatedly demonstrated that backup existence ≠ recovery capability. Immutable backups and tested restore procedures are the de facto baseline."
      },
      "ucpa": {
        "effectiveness": 0.81,
        "breadth": 0.76,
        "resilience": 0.98,
        "env_tags": [
          "tx_k12"
        ],
        "aggregation_rule": "max_of_underlying"
      },
      "crosswalks": {
        "nist_800_53_r5": [
          {
            "target_id": "800-53:CP-2",
            "target_name": "Contingency Plan",
            "relationship": "equivalent",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CP-4",
            "target_name": "Contingency Plan Testing",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CP-9",
            "target_name": "System Backup",
            "relationship": "subset_of",
            "confidence": "high"
          },
          {
            "target_id": "800-53:CP-10",
            "target_name": "System Recovery and Reconstitution",
            "relationship": "equivalent",
            "confidence": "high"
          }
        ]
      },
      "maturity_rubric": {
        "level_0": {
          "description": "Disaster Recovery Procedures is not addressed. No documented process exists.",
          "indicators": [
            "No documented process or policy",
            "No designated responsibility",
            "No artifacts or evidence available"
          ]
        },
        "level_1": {
          "description": "Disaster Recovery Procedures is performed informally and inconsistently. Outcomes depend on individual effort.",
          "indicators": [
            "Practices exist but are undocumented",
            "Inconsistent execution across the organization",
            "Reactive rather than planned"
          ]
        },
        "level_2": {
          "description": "Disaster Recovery Procedures is planned and documented. Procedures exist but are not yet uniformly followed.",
          "indicators": [
            "Documented procedures exist",
            "Roles and responsibilities defined",
            "Implementation in progress but not complete"
          ]
        },
        "level_3": {
          "description": "DR plan exercised annually. Immutable/offline backups for ransomware resilience. Defined RPO/RTO. Critical system recovery validated.",
          "indicators": [
            "Annual DR exercise documented",
            "Immutable or air-gapped backup tier",
            "Defined RPO/RTO per system tier",
            "Successful restore of mission-critical data within RTO"
          ]
        },
        "level_4": {
          "description": "Disaster Recovery Procedures is measured with quantitative metrics. Performance is predictable and managed.",
          "indicators": [
            "Quantitative performance metrics tracked",
            "Trends reviewed by leadership",
            "Deviations investigated and addressed"
          ]
        },
        "level_5": {
          "description": "Disaster Recovery Procedures is continuously improved through data-driven optimization, automation, and root-cause analysis.",
          "indicators": [
            "Continuous improvement program in place",
            "Automation reduces manual effort",
            "Improvements measured and sustained"
          ]
        }
      },
      "evidence_artifacts": [
        "Disaster recovery plan",
        "Annual DR exercise after-action report",
        "Backup architecture diagram (showing immutability/air-gap)",
        "RPO/RTO documentation per system",
        "Restore test logs"
      ],
      "tags": [
        "recovery",
        "backups",
        "ransomware_resilience",
        "k12_critical"
      ]
    }
  ]
}
