π§ͺ E8 Assessment Framework Test Plan¶
Executive Summary¶
This test plan validates the Essential Eight (E8) Assessment Framework's ability to deliver on its core promises:
- 85% pre-completion through triple-crossover intelligence
- Intelligent routing (IT: ~35 questions, Board: ~5 questions)
- Accurate maturity level calculations
- Board-friendly 2-3 minute decision process
Test Objectives¶
Primary Objectives¶
- Validate Mapping Accuracy: Ensure 152 ACSC controls correctly map to 40 questions
- Verify Pre-fill Engine: Confirm 85% pre-completion from crossover sources
- Test Role Routing: Validate questions route to appropriate stakeholders
- Confirm Board Experience: Ensure board interface delivers 2-3 minute decision capability
- Validate Maturity Calculations: Verify ML0-ML3 calculations match ACSC guidance
Secondary Objectives¶
- Document integration points with UQB
- Validate audit trail completeness
- Confirm delegation workflows
- Test edge cases and failure modes
Test Scope¶
In Scope¶
- All 40 E8 assessment questions
- Triple-crossover intelligence (policies, insurance, prior assessments)
- Role-based routing logic
- Maturity level calculations
- Board presentation layer
- Audit trail generation
Out of Scope¶
- UI implementation (covered in Task 86)
- API performance testing (pre-code phase)
- Load testing (single-tenant MVP)
- Integration with external systems
Test Methodology¶
1. Document-Based Validation¶
Since GetCimple is in documentation phase, testing involves:
- Walking through scenarios on paper
- Validating logic flows
- Checking mathematical calculations
- Reviewing mapping accuracy
2. Scenario-Based Testing¶
Three representative scenarios:
- Small business (10 employees, no board)
- Medium enterprise (50 employees with board)
- Regulated entity (financial services with compliance requirements)
3. Coverage Analysis¶
- Ensure all 152 ACSC controls have representation
- Verify all 8 E8 strategies are assessed
- Confirm all maturity levels are achievable
Test Scenarios¶
Scenario 1: Small Business (TechStartup Pty Ltd)¶
Profile: 10-person SaaS startup, no formal board, basic IT setup
Test Points:
- Pre-fill from basic policies (expect 30-40% completion)
- All questions route to IT manager/founder
- Simplified maturity view (no board interface)
- Target setting by management only
- Quick wins identified for ML1
Expected Outcomes:
- Current maturity: ML0-ML1 mix
- Completion time: 20-25 minutes
- Pre-fill rate: 35%
- Recommended target: ML1 across all strategies
Scenario 2: Medium Enterprise (MedCorp Limited)¶
Profile: 50 employees, board with 5 directors, IT team of 3
Test Points:
- Pre-fill from policies and cyber insurance (expect 70% completion)
- Technical questions route to IT team
- Governance questions escalate to board
- Board sees "90% complete by IT"
- Clear ML2 pathway presented
Expected Outcomes:
- Current maturity: ML1-ML2 mix
- Board decision time: 2-3 minutes
- Pre-fill rate: 70%
- Recommended target: ML2 for critical strategies
Scenario 3: Regulated Entity (FinanceCore Pty Ltd)¶
Profile: 100 employees, regulated by APRA, mature governance
Test Points:
- Pre-fill from comprehensive sources (expect 85% completion)
- Complex routing through compliance team
- Board focus on ML2+ compliance
- Regulatory alignment validation
- Advanced maturity options presented
Expected Outcomes:
- Current maturity: ML2 baseline
- Board review time: 3-5 minutes
- Pre-fill rate: 85%
- Mandatory target: ML2 minimum, ML3 for critical
Success Criteria¶
Functional Criteria¶
- β All 40 questions map to ACSC controls
- β Pre-fill achieves 60%+ average across scenarios
- β Role routing accuracy > 95%
- β Board decision time < 5 minutes
- β Maturity calculations align with ACSC model
Quality Criteria¶
- β No ambiguous questions
- β Clear delegation paths
- β Audit trail captures all decisions
- β Board language is non-technical
- β Recommendations are actionable
Test Execution Timeline¶
Phase 1: Mapping Validation (2 hours)¶
- Review 152 β 40 control mapping
- Verify coverage of all E8 strategies
- Document any gaps or overlaps
Phase 2: Scenario Execution (3 hours)¶
- Walk through each scenario
- Document question routing
- Calculate pre-fill rates
- Time board decision process
Phase 3: Results Documentation (1 hour)¶
- Compile test results
- Document findings
- Create recommendations
- Update framework documentation
Risk Assessment¶
High Risk Areas¶
-
Pre-fill Accuracy: May not achieve 85% target
-
Mitigation: Set realistic expectations (60-85% range)
-
Board Complexity: 5 questions may still be too many
-
Mitigation: Create executive summary option
-
Maturity Calculation: Edge cases in ML determination
- Mitigation: Document calculation rules clearly
Medium Risk Areas¶
-
Role Ambiguity: Some questions span multiple roles
-
Mitigation: Allow collaborative answering
-
Crossover Conflicts: Different sources give different answers
- Mitigation: Implement confidence scoring
Test Deliverables¶
- Test Execution Report: Results from all scenarios
- Validation Checklist: Completed validation items
- Gap Analysis: Any framework deficiencies found
- Recommendations: Improvements for implementation
- Audit Documentation: Evidence of testing completion
Conclusion¶
This test plan ensures the E8 Assessment Framework delivers on its promises before UI implementation begins. Focus is on validating the core logic, routing accuracy, and board experience rather than technical implementation details.