| AC | AC-2, AC-3, AC-5, AC-6, AC-17 | Role-based and attribute-aware access, least privilege, separation of duties, quarterly access reviews, protected production access. | IdP exports, GitHub team exports, CODEOWNERS, branch protection exports, Kubernetes RBAC, access-review issues. | IdP, GitHub, Kubernetes RBAC, Kyverno | Partially Implemented | Confirm authoritative identity source and automate stale-account reports. |
| IA | IA-2, IA-5, IA-12 | Federated identity, MFA, privileged phishing-resistant MFA, credential lifecycle, proofing where required. | MFA policy export, IdP configuration, authenticator inventory, login audit logs. | Keycloak or Authentik, WebAuthn, PIV/CAC where required | Planned | Select IdP pattern and document assurance level. |
| AU | AU-2, AU-3, AU-6, AU-9, AU-11, AU-12 | Security-relevant events logged centrally with schema, retention, alerting, and integrity protection. | Log schema, sample events, retention settings, alert rules, review records. | OpenTelemetry, Loki or equivalent, Grafana, Wazuh candidate | Planned | Define audit event schema and retention target. |
| CA | CA-2, CA-3, CA-7 | Assessment evidence, third-party connections, and continuous monitoring tracked as living artifacts. | ConMon package, 3PAO assessment artifacts, interconnection agreements, monthly review issues. | OSCAL, Trestle, GitHub Issues, dashboards | Planned | Build evidence inventory and monthly package format. |
| CM | CM-2, CM-3, CM-4, CM-5, CM-6, CM-8 | Baselines as code, reviewed changes, drift detection, inventory, and least-privilege change execution. | Pull requests, approvals, workflow logs, Argo CD sync history, inventory exports. | GitHub Actions, Helm, Argo CD, OpenTofu, Kyverno | Partially Implemented | Add baseline inventory and drift evidence. |
| CP | CP-2, CP-9, CP-10 | Contingency plan, encrypted backups, restore tests, RTO and RPO targets. | Backup job history, restore-test results, DR exercise records. | Velero, pgBackRest, object storage lifecycle | Planned | Define RTO, RPO, and restore-test cadence. |
| IR | IR-4, IR-5, IR-6, IR-8 | Incident plan, triage, communications, reporting, lessons learned, and evidence retention. | Incident tickets, timelines, post-incident reviews, notification records. | GitHub Issues or incident tracker, Grafana, alerting | Planned | Create incident severity model and reporting runbook. |
| RA | RA-3, RA-5, RA-7 | Risk assessment, recurring vulnerability scanning, risk response, and remediation tracking. | Scan reports, risk register, POA&M entries, exception approvals. | Trivy, Grype, ZAP, OpenSCAP, kube-bench, Semgrep | Planned | Define scan scope and finding SLAs. |
| SA | SA-10, SA-11, SA-15 | Secure development process, code review, test evidence, security scanning, and developer standards. | Pull requests, test results, SAST results, DAST results, secure coding guidance. | GitHub Actions, CodeQL, Semgrep, Vitest, Playwright, ZAP | Partially Implemented | Gate releases on security findings. |
| SC | SC-7, SC-8, SC-12, SC-13, SC-28 | Boundary protection, TLS, internal segmentation, secrets, key management, encryption at rest. | TLS scan, network policies, secret rotation logs, KMS configuration, storage encryption export. | Kubernetes NetworkPolicy, Kyverno, cert-manager, Vault candidate | Planned | Confirm FIPS module status and internal mTLS plan. |
| SI | SI-2, SI-3, SI-4, SI-7, SI-10 | Flaw remediation, malware protection, monitoring, integrity, and input validation. | Scan findings, remediation tickets, alert history, admission-control results, validation tests. | Trivy, Falco, OpenTelemetry, Zod, Playwright, Vitest | Partially Implemented | Tie findings to POA&M and SLA evidence. |
| SR | SR-3, SR-4, SR-5, SR-11 | Supplier review, SBOM, provenance, signed artifacts, and dependency governance. | SBOM, provenance attestations, signed images, dependency review records. | Syft, cosign, SLSA generator, Scorecard, Renovate | Planned | Add SBOM and signing pipeline. |
| PT | PT-2, PT-3, PT-4, PT-5 | PII authority, minimization, consent, retention, and privacy notices. | Data inventory, privacy review, retention schedule, deletion evidence. | Data inventory, database migrations, audit logs | Planned | Confirm PII categories and privacy owner. |
| PL | PL-2, PL-4, PL-8 | Security plan, rules of behavior, and security architecture maintained. | SSP, boundary diagram, signed rules of behavior, architecture review. | Markdown docs, ADRs, diagrams, OSCAL candidate | Partially Implemented | Convert template docs into controlled package artifacts. |
| PM | PM-4, PM-5, PM-9, PM-10 | POA&M process, inventory, risk strategy, and authorization process governance. | POA&M, system inventory, risk acceptance records, authorization plan. | GitHub Projects, OSCAL, dashboards | Planned | Assign governance owners and cadence. |