Findings register
12 controls evaluated
| Control | Status | Risk | Missing elements | POA&M | Action |
|---|---|---|---|---|---|
AC-2 Account Management No assessment row exists for this control. | Not Assessed | Not Assessed | Documented approval workflow; Quarterly account review; Automated disablement of inactive accounts | — | No action required. |
AC-6 Least Privilege No assessment row exists for this control. | Not Assessed | Not Assessed | Role definitions mapped to duties; Privileged role review; Just-in-time elevation | — | No action required. |
AU-6 Audit Review, Analysis, and Reporting No assessment row exists for this control. | Not Assessed | Not Assessed | Defined review frequency; Named reviewer role; Documented escalation of anomalies | — | No action required. |
CM-6 Configuration Settings No assessment row exists for this control. | Not Assessed | Not Assessed | Documented baseline per component; Automated compliance scanning; Deviation approval record | — | No action required. |
CP-9 System Backup No assessment row exists for this control. | Not Assessed | Not Assessed | Backup schedule; Offsite/immutable copy; Documented restore test results | — | No action required. |
IA-2 Identification and Authentication (Organizational Users) No assessment row exists for this control. | Not Assessed | Not Assessed | Unique user IDs; MFA for all users; Phishing-resistant factors for privileged access | — | No action required. |
IR-4 Incident Handling No assessment row exists for this control. | Not Assessed | Not Assessed | Documented IR plan; Annual tabletop exercise; US-CERT reporting timelines | — | No action required. |
RA-5 Vulnerability Monitoring and Scanning No assessment row exists for this control. | Not Assessed | Not Assessed | Monthly authenticated scans; High/Critical remediation SLA tracking; Scanner signature currency | — | No action required. |
SC-13 Cryptographic Protection No assessment row exists for this control. | Not Assessed | Not Assessed | FIPS 140-validated modules; TLS 1.2+ enforced; Key management procedures | — | No action required. |
SI-2 Flaw Remediation No assessment row exists for this control. | Not Assessed | Not Assessed | Patch SLA by severity; Measured mean-time-to-patch; Emergency patch procedure | — | No action required. |
SI-4 System Monitoring No assessment row exists for this control. | Not Assessed | Not Assessed | Boundary monitoring; Identity telemetry; Alerting to named responders | — | No action required. |
AT-2 Literacy Training and Awareness No assessment row exists for this control. | Not Assessed | Not Assessed | Initial training before access; Annual refresh; Retained completion records | — | No action required. |