CTAF
Meridian Health Analytics · NIST 800-53 Rev5 / FedRAMP ModerateSign in to save
Alignment_Check · Derived Output

Findings are computed, never entered

Each row is the deterministic output of the CTAF rules layer against the submitted observation. Change the evidence and the finding recomputes; the finding itself is read-only.

Findings register

12 controls evaluated

ControlStatusRiskMissing elementsPOA&MAction
AC-2
Account Management
No assessment row exists for this control.
Not AssessedNot AssessedDocumented approval workflow; Quarterly account review; Automated disablement of inactive accounts—No action required.
AC-6
Least Privilege
No assessment row exists for this control.
Not AssessedNot AssessedRole definitions mapped to duties; Privileged role review; Just-in-time elevation—No action required.
AU-6
Audit Review, Analysis, and Reporting
No assessment row exists for this control.
Not AssessedNot AssessedDefined review frequency; Named reviewer role; Documented escalation of anomalies—No action required.
CM-6
Configuration Settings
No assessment row exists for this control.
Not AssessedNot AssessedDocumented baseline per component; Automated compliance scanning; Deviation approval record—No action required.
CP-9
System Backup
No assessment row exists for this control.
Not AssessedNot AssessedBackup schedule; Offsite/immutable copy; Documented restore test results—No action required.
IA-2
Identification and Authentication (Organizational Users)
No assessment row exists for this control.
Not AssessedNot AssessedUnique user IDs; MFA for all users; Phishing-resistant factors for privileged access—No action required.
IR-4
Incident Handling
No assessment row exists for this control.
Not AssessedNot AssessedDocumented IR plan; Annual tabletop exercise; US-CERT reporting timelines—No action required.
RA-5
Vulnerability Monitoring and Scanning
No assessment row exists for this control.
Not AssessedNot AssessedMonthly authenticated scans; High/Critical remediation SLA tracking; Scanner signature currency—No action required.
SC-13
Cryptographic Protection
No assessment row exists for this control.
Not AssessedNot AssessedFIPS 140-validated modules; TLS 1.2+ enforced; Key management procedures—No action required.
SI-2
Flaw Remediation
No assessment row exists for this control.
Not AssessedNot AssessedPatch SLA by severity; Measured mean-time-to-patch; Emergency patch procedure—No action required.
SI-4
System Monitoring
No assessment row exists for this control.
Not AssessedNot AssessedBoundary monitoring; Identity telemetry; Alerting to named responders—No action required.
AT-2
Literacy Training and Awareness
No assessment row exists for this control.
Not AssessedNot AssessedInitial training before access; Annual refresh; Retained completion records—No action required.

Local demo workspace (browser-local) — sign in to keep an isolated, durable record per organization.