Overview
Scoped to Prod Web Enclave under CMMC 2.0 — switch the system or framework up top to re-scope everything.
◎ Framework score
68%
75 of 110 requirements met
✔ Controls
35
need attention
13 partial
22 gap
◎ Tests
7
failing of 42 automated
35 passing
7 failing
▧ Documents
5
drafts of 23
18 published
◷ POA&M
6
open items · 2 overdue
Systems in scope
🖥 Prod Web Enclave
Debian 13 · web+api
CMMC 68%SOC2 54%
🖥 CI Runner Pool
Rocky 9 · build
CMMC 51%
🖥 Corp Laptops
Windows 11 · endpoints
CMMC 33%
Controls
The requirement is the row; the Tests column links the automated checks that evidence it, and Evidence is what an assessor opens first.
Status: All ▾
Family: All ▾
Owner: All ▾
| Control | Requirement | Status | Tests | Evidence | Owner |
|---|---|---|---|---|---|
| 3.1.1 | Limit system access to authorized users Access Control |
● Met | 3 passing | ▧ IAM policy | AV Alex Vega |
| 3.1.5 | Least privilege Access Control |
● Partial | 1 failing | None recorded | JR Jordan Rowe |
| 3.4.2 | Enforce baseline configuration Configuration Mgmt |
● Met | 6 passing | ◎ Salt cmmc_report | AV Alex Vega |
| 3.5.3 | Multi-factor authentication Identification & Auth |
● Gap | 2 failing | None recorded | Unassigned |
| 3.8.9 | Protect backups of CUI Media Protection |
● N/A | — | ▧ Boundary note | JR Jordan Rowe |
| 3.13.11 | FIPS-validated cryptography System & Comms |
● Partial | 2 passing | ▧ Cipher config | AV Alex Vega |
| 3.14.1 | Flaw remediation System & Info Integrity |
● Gap | 1 failing | None recorded | JR Jordan Rowe |
Tests
Automated checks reported by the Salt runner on Prod Web Enclave. Each maps to the control(s) it evidences — a passing test is evidence, not a control status by itself.
Result: All ▾
Host: Prod Web Enclave ▾
| Test | Result | Last run | Covers | Host |
|---|---|---|---|---|
SSH root login disabled sshd_permitrootlogin |
✓ Pass | 14m ago | 3.1.1 3.5.3 | Prod Web Enclave |
Password quality (pwquality) pam_pwquality_minlen |
✓ Pass | 14m ago | 3.5.7 | Prod Web Enclave |
MFA enrolled for privileged users mfa_priv_enrolled |
✕ Fail | 14m ago | 3.5.3 | Prod Web Enclave |
Automatic security updates unattended_upgrades |
✕ Fail | 14m ago | 3.14.1 | Prod Web Enclave |
Firewall default-deny inbound nftables_default_deny |
✓ Pass | 14m ago | 3.13.1 3.13.5 | Prod Web Enclave |
Audit daemon running (auditd) auditd_active |
✓ Pass | 14m ago | 3.3.1 | Prod Web Enclave |
Documents
Policies, uploaded evidence, and the org's SSP / POA&M in one place — the paper an assessor asks for, with its status and owner.
Type: All ▾
Status: All ▾
| Title | Type | Status | Updated | Owner |
|---|---|---|---|---|
| Access Control Policy | Policy | ● Published | Aug 9 | AV Alex Vega |
| System Security Plan (SSP) | SSP | ● Draft | Aug 11 | JR Jordan Rowe |
| Plan of Action & Milestones | POA&M | ● Current | Aug 11 | AV Alex Vega |
| Nessus scan — 2026-08-10.pdf | Evidence | ● Accepted | Aug 10 | JR Jordan Rowe |
| Incident Response Plan | Policy | ● Missing | — | Unassigned |
Policies
Read your org's policies any time — check a scenario against them, refresh your memory before you act. Everyone can read; owners and admins can edit. Use the toggle to preview each view.
Preview as:
Access Control Policy
Access Control · v3 ● Acknowledged
Acceptable Use Policy
Governance · v2 ● Not read
Data Handling & Classification
Data Protection · v4 ● Acknowledged
Incident Response Policy
Security Ops · v1 ● Not read
Password & MFA Policy
Identity · v2 ● Acknowledged
Access Control Policy
Access Control · updated Aug 9, 2026 · version 3 · owner Alex Vega
This policy governs how access to Acme systems and Controlled Unclassified Information (CUI) is granted, reviewed, and revoked. It applies to all members, contractors, and automated identities.
Least privilege
Access is granted on a need-to-know basis. A person or service receives only the permissions required for their current role, and elevated access is time-bound and logged.
Multi-factor authentication
MFA is required for all privileged access and for any access to systems that store or process CUI. A scenario you're unsure about — "can I use a shared login for the CI runner?" — is answered here: no, individual accounts with MFA only.
Review & revocation
Access is reviewed quarterly and on any role change. Departures trigger same-day revocation across all systems in scope.
🕑 You acknowledged this policy on Aug 9, 2026. Re-read any time — your acknowledgment stands until the policy changes.
Editing is restricted to owners and admins. Members see this read-only, with an Acknowledge button and their acknowledgment history.
Registers
Your existing register program (the editors you already have), grouped so the rail isn't a wall of fourteen items. This is the "program" content, kept but tidied.
Security ownership
RACI · responsibilities · authority
Data & flows
Data inventory · data flow · access-control matrix
Engineering
DevSecOps evidence · dependencies · logging design
Risk & decisions
Assumptions · decisions · corrective actions
Incidents
Incident register
Maturity & gov
Maturity assessment · FOCI · gov worksheet
Roadmap
Open items with a target date — the same data as the POA&M document, worked as a list.
| Item | Status | Target | Owner |
|---|---|---|---|
| Enroll all privileged users in MFA (3.5.3) | ● Overdue | Aug 8 | AV Alex Vega |
| Enable unattended security updates (3.14.1) | ● In progress | Aug 20 | JR Jordan Rowe |
| Author Incident Response Plan | ● Not started | Sep 1 | Unassigned |
People
Who's acknowledged which policy and completed which training — the roster, for the human controls.
| Member | Role | Policies | Training |
|---|---|---|---|
| AV Alex Vega | Owner | ● 6/6 | ● 3/3 |
| JR Jordan Rowe | Admin | ● 4/6 | ● 3/3 |
| SO Sam Okafor | Editor | ● 1/6 | ● 0/3 |