CTAF
Meridian Health Analytics · NIST 800-53 Rev5 / FedRAMP ModerateSign in to save
Assessment Workspace · Evidence Intake

Assess each control with its reference context in view

Control_Translation guidance sits beside the Assessment_Working intake. The deterministic decision engine classifies as you type — nothing is hand-edited downstream.

Control library
Access Control · AC-2

Account Management

Not Assessed
Plain English
You must know every account on the system, who approved it, and prove you review them on a schedule.
Why this matters
Orphaned and over-privileged accounts are the most common initial access path in federal breach reports.
Common failure
Accounts created ad hoc via ticket with no documented approver and no recurring recertification.
Required SSP language
The organization defines account types, assigns account managers, requires approvals for account creation, and reviews accounts quarterly.
Indicators
Documented approval workflowQuarterly account reviewAutomated disablement of inactive accounts
Assessment_Working

Implementation evidence

ctaf-rules-v1.0 (workbook parity)

Decision engine preview

Status
Not Assessed
Risk
Not Assessed
POA&M needed
No

Rule trace: No assessment row exists for this control.

Known limitation (Handoff §5.1): keyword precedence reproduces the workbook exactly, so phrasing like "no gaps identified" classifies as Not Met. Parity is intentional pending an explicit customer decision.

Local demo workspace (browser-local) — sign in to keep an isolated, durable record per organization.