Skip to content

Control Implementation Matrix

This matrix is a template traceability tool. Keep it aligned with the repo-level ATO control alignment, then expand it into per-control implementation statements in the official SSP template.

Status Vocabulary

StatusMeaning
ImplementedBehavior exists and evidence is produced by a repeatable process.
Partially ImplementedBehavior exists but evidence, automation, coverage, or enhancement support is incomplete.
PlannedThe control is intended but not yet implemented.
InheritedThe control is provided by a third party and provider evidence exists.
Shareddmwd.io and a provider each own part of the control.
Not ApplicableThe control does not apply to the final boundary and rationale is documented.

Family Matrix

FamilyKey ControlsTarget ImplementationPrimary EvidenceToolsCurrent StatusGap
ACAC-2, AC-3, AC-5, AC-6, AC-17Role-based and attribute-aware access, least privilege, separation of duties, quarterly access reviews, protected production access.IdP exports, GitHub team exports, CODEOWNERS, branch protection exports, Kubernetes RBAC, access-review issues.IdP, GitHub, Kubernetes RBAC, KyvernoPartially ImplementedConfirm authoritative identity source and automate stale-account reports.
IAIA-2, IA-5, IA-12Federated identity, MFA, privileged phishing-resistant MFA, credential lifecycle, proofing where required.MFA policy export, IdP configuration, authenticator inventory, login audit logs.Keycloak or Authentik, WebAuthn, PIV/CAC where requiredPlannedSelect IdP pattern and document assurance level.
AUAU-2, AU-3, AU-6, AU-9, AU-11, AU-12Security-relevant events logged centrally with schema, retention, alerting, and integrity protection.Log schema, sample events, retention settings, alert rules, review records.OpenTelemetry, Loki or equivalent, Grafana, Wazuh candidatePlannedDefine audit event schema and retention target.
CACA-2, CA-3, CA-7Assessment evidence, third-party connections, and continuous monitoring tracked as living artifacts.ConMon package, 3PAO assessment artifacts, interconnection agreements, monthly review issues.OSCAL, Trestle, GitHub Issues, dashboardsPlannedBuild evidence inventory and monthly package format.
CMCM-2, CM-3, CM-4, CM-5, CM-6, CM-8Baselines as code, reviewed changes, drift detection, inventory, and least-privilege change execution.Pull requests, approvals, workflow logs, Argo CD sync history, inventory exports.GitHub Actions, Helm, Argo CD, OpenTofu, KyvernoPartially ImplementedAdd baseline inventory and drift evidence.
CPCP-2, CP-9, CP-10Contingency plan, encrypted backups, restore tests, RTO and RPO targets.Backup job history, restore-test results, DR exercise records.Velero, pgBackRest, object storage lifecyclePlannedDefine RTO, RPO, and restore-test cadence.
IRIR-4, IR-5, IR-6, IR-8Incident plan, triage, communications, reporting, lessons learned, and evidence retention.Incident tickets, timelines, post-incident reviews, notification records.GitHub Issues or incident tracker, Grafana, alertingPlannedCreate incident severity model and reporting runbook.
RARA-3, RA-5, RA-7Risk assessment, recurring vulnerability scanning, risk response, and remediation tracking.Scan reports, risk register, POA&M entries, exception approvals.Trivy, Grype, ZAP, OpenSCAP, kube-bench, SemgrepPlannedDefine scan scope and finding SLAs.
SASA-10, SA-11, SA-15Secure development process, code review, test evidence, security scanning, and developer standards.Pull requests, test results, SAST results, DAST results, secure coding guidance.GitHub Actions, CodeQL, Semgrep, Vitest, Playwright, ZAPPartially ImplementedGate releases on security findings.
SCSC-7, SC-8, SC-12, SC-13, SC-28Boundary protection, TLS, internal segmentation, secrets, key management, encryption at rest.TLS scan, network policies, secret rotation logs, KMS configuration, storage encryption export.Kubernetes NetworkPolicy, Kyverno, cert-manager, Vault candidatePlannedConfirm FIPS module status and internal mTLS plan.
SISI-2, SI-3, SI-4, SI-7, SI-10Flaw remediation, malware protection, monitoring, integrity, and input validation.Scan findings, remediation tickets, alert history, admission-control results, validation tests.Trivy, Falco, OpenTelemetry, Zod, Playwright, VitestPartially ImplementedTie findings to POA&M and SLA evidence.
SRSR-3, SR-4, SR-5, SR-11Supplier review, SBOM, provenance, signed artifacts, and dependency governance.SBOM, provenance attestations, signed images, dependency review records.Syft, cosign, SLSA generator, Scorecard, RenovatePlannedAdd SBOM and signing pipeline.
PTPT-2, PT-3, PT-4, PT-5PII authority, minimization, consent, retention, and privacy notices.Data inventory, privacy review, retention schedule, deletion evidence.Data inventory, database migrations, audit logsPlannedConfirm PII categories and privacy owner.
PLPL-2, PL-4, PL-8Security plan, rules of behavior, and security architecture maintained.SSP, boundary diagram, signed rules of behavior, architecture review.Markdown docs, ADRs, diagrams, OSCAL candidatePartially ImplementedConvert template docs into controlled package artifacts.
PMPM-4, PM-5, PM-9, PM-10POA&M process, inventory, risk strategy, and authorization process governance.POA&M, system inventory, risk acceptance records, authorization plan.GitHub Projects, OSCAL, dashboardsPlannedAssign governance owners and cadence.

Control Claim Template

Use this template when expanding a row into an SSP control statement.

FieldContent
Control ID[FILL IN]
Status[Implemented, Partially Implemented, Planned, Inherited, Shared, or Not Applicable]
Implementation[FILL IN: what the system does, where enforced, and who owns it]
Evidence[FILL IN: exact evidence artifact and storage location]
Inheritance[FILL IN: provider and package evidence, or None]
Open Gap[FILL IN: gap or None]
POA&M Item[FILL IN: ID or None]
Review Cadence[FILL IN]

Evidence Quality Bar

  • Evidence is generated during normal engineering or operations work.
  • Evidence names the system, environment, date, owner, and control relationship.
  • Evidence is retained in a durable repository or object store.
  • Evidence can be reproduced for a monthly ConMon package.
  • Evidence is not only a screenshot when an API export or machine-readable report is available.