Control mapping

Each control we track, the frameworks it supports, how far along it is, and the evidence. This mapping is our own work and has not been independently audited. It is not a certification.

169 controls shown

Security controls with framework, status and evidence
ControlTitleFrameworksStatusEvidence
AC-1Access ControlPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/access-control.md (DRAFT)
AC-2Access ControlAccount Management
  • NIST 800-53
  • SOC 2
Partialcontrols/evidence/2026-10-09-access-app.json; GitHub org members; access review record (planned)
AC-3Access ControlAccess Enforcement
  • NIST 800-53
  • SOC 2
Implementedcontrols/evidence/2026-10-09-access-app.json; worker/src/admin.ts; worker/test/api.test.ts
AC-4Access ControlInformation Flow Enforcement
  • NIST 800-53
  • SOC 2
Implementedworker/src/security.ts; worker/src/public.ts (same-origin guard); scripts/check-headers.sh; .github/workflows/ci.yml (post-deploy header check)
AC-5Access ControlSeparation of Duties
  • NIST 800-53
PartialGitHub environment 'production' protection rule
AC-6Access ControlLeast Privilege
  • NIST 800-53
  • SOC 2
Partial.github/workflows/ci.yml (permissions block)
AC-7Access ControlUnsuccessful Logon Attempts
  • NIST 800-53
Partialworker/wrangler.jsonc (ratelimits); worker/src/public.ts; worker/test/api.test.ts; controls/evidence/2026-10-09-access-app.json
AC-8Access ControlSystem Use Notification
  • NIST 800-53
PlannedAdmin page banner (planned)
AC-11Access ControlDevice Lock
  • NIST 800-53
Plannedcontrols/policies/acceptable-use.md (DRAFT)
AC-12Access ControlSession Termination
  • NIST 800-53
Implementedcontrols/evidence/2026-10-09-access-app.json
AC-14Access ControlPermitted Actions Without Identification or Authentication
  • NIST 800-53
Implementedcontrols/nist-800-53-moderate.csv; site map
AC-17Access ControlRemote Access
  • NIST 800-53
  • SOC 2
Partialcontrols/evidence/2026-10-09-access-app.json; worker/src/admin.ts; .github/workflows/ci.yml (deploy job); GitHub org 2FA setting (to capture)
AC-20Access ControlUse of External Systems
  • NIST 800-53
Partialcontrols/policies/vendor-management.md (DRAFT)
AC-21Access ControlInformation Sharing
  • NIST 800-53
  • SOC 2
Partialprivacy.html; controls/policies/data-retention-privacy.md (DRAFT)
AC-22Access ControlPublicly Accessible Content
  • NIST 800-53
Implementedcontrols/evidence/2026-10-09-github-protections.json; .github/CODEOWNERS; .github/workflows/ci.yml; scripts/apply-github-protections.sh
AT-1Awareness and TrainingPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/information-security.md (DRAFT)
AT-2Awareness and TrainingLiteracy Training and Awareness
  • NIST 800-53
  • SOC 2
PlannedTraining record (planned)
AT-3Awareness and TrainingRole-Based Training
  • NIST 800-53
  • SOC 2
PlannedTraining record (planned)
AT-4Awareness and TrainingTraining Records
  • NIST 800-53
PlannedTraining record (planned)
AU-1Audit and AccountabilityPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/information-security.md (DRAFT)
AU-2Audit and AccountabilityEvent Logging
  • NIST 800-53
  • SOC 2
Implementedworker/src/auditchain.ts; worker/src/maintenance.ts; worker/test/hardening.test.ts
AU-3Audit and AccountabilityContent of Audit Records
  • NIST 800-53
Implementedworker/migrations/0001_init.sql; worker/migrations/0002_audit_hash_chain.sql; worker/src/auditchain.ts
AU-4Audit and AccountabilityAudit Log Storage Capacity
  • NIST 800-53
  • SOC 2
PartialD1 usage dashboard
AU-5Audit and AccountabilityResponse to Audit Logging Process Failures
  • NIST 800-53
PlannedAlert rule (planned)
AU-6Audit and AccountabilityAudit Record Review, Analysis, and Reporting
  • NIST 800-53
  • SOC 2
PlannedAudit review record (planned)
AU-7Audit and AccountabilityAudit Record Reduction and Report Generation
  • NIST 800-53
PlannedSaved D1 queries (planned)
AU-8Audit and AccountabilityTime Stamps
  • NIST 800-53
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04)
AU-9Audit and AccountabilityProtection of Audit Information
  • NIST 800-53
Partialworker/src/auditchain.ts (verifyChain); worker/src/maintenance.ts; worker/test/hardening.test.ts
AU-11Audit and AccountabilityAudit Record Retention
  • NIST 800-53
  • SOC 2
Partialworker/src/maintenance.ts (RETENTION_DAYS, KEEP_BACKUPS); controls/policies/data-retention-privacy.md (DRAFT)
AU-12Audit and AccountabilityAudit Record Generation
  • NIST 800-53
  • SOC 2
Implementedworker/src/auditchain.ts; worker/src/public.ts; worker/test/hardening.test.ts
CA-1Assessment, Authorization, and MonitoringPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/information-security.md (DRAFT)
CA-2Assessment, Authorization, and MonitoringControl Assessments
  • NIST 800-53
  • SOC 2
Partial.github/workflows/ci.yml
CA-3Assessment, Authorization, and MonitoringInformation Exchange
  • NIST 800-53
  • SOC 2
Partialcontrols/vendor-register.md (DRAFT); controls/inventory.md (DRAFT)
CA-5Assessment, Authorization, and MonitoringPlan of Action and Milestones
  • NIST 800-53
  • SOC 2
Partialcontrols/GAPS.md
CA-6Assessment, Authorization, and MonitoringAuthorization
  • NIST 800-53
  • SOC 2
PlannedAuthorization memo (planned)
CA-7Assessment, Authorization, and MonitoringContinuous Monitoring
  • NIST 800-53
  • SOC 2
Implemented.github/workflows/scheduled-security.yml; .github/workflows/ci.yml
CA-9Assessment, Authorization, and MonitoringInternal System Connections
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
CM-1Configuration ManagementPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/change-management.md (DRAFT)
CM-2Configuration ManagementBaseline Configuration
  • NIST 800-53
  • SOC 2
Implementedwrangler config; .github/workflows/ci.yml
CM-3Configuration ManagementConfiguration Change Control
  • NIST 800-53
  • SOC 2
Implementedcontrols/evidence/2026-10-09-github-protections.json; .github/pull_request_template.md; .github/workflows/ci.yml; scripts/apply-github-protections.sh
CM-4Configuration ManagementImpact Analyses
  • NIST 800-53
  • SOC 2
Partial.github/pull_request_template.md
CM-5Configuration ManagementAccess Restrictions for Change
  • NIST 800-53
  • SOC 2
Partialcontrols/evidence/2026-10-09-github-protections.json; .github/CODEOWNERS
CM-6Configuration ManagementConfiguration Settings
  • NIST 800-53
  • SOC 2
Implementedscripts/check-headers.sh; scripts/check-cloudflare-baseline.sh; controls/evidence/2026-10-09-cloudflare-baseline.json
CM-7Configuration ManagementLeast Functionality
  • NIST 800-53
  • SOC 2
Implementedworker/src/index.ts; worker/src/security.ts; worker/test/hardening.test.ts
CM-8Configuration ManagementSystem Component Inventory
  • NIST 800-53
Partialcontrols/inventory.md (DRAFT); .github/workflows/ci.yml (sbom job)
CM-9Configuration ManagementConfiguration Management Plan
  • NIST 800-53
Plannedcontrols/policies/change-management.md (DRAFT)
CM-10Configuration ManagementSoftware Usage Restrictions
  • NIST 800-53
PlannedLicense check (planned)
CP-1Contingency PlanningPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/incident-response.md (DRAFT)
CP-2Contingency PlanningContingency Plan
  • NIST 800-53
  • SOC 2
Partialcontrols/runbooks/contingency-plan.md (DRAFT); worker/RUNBOOK-restore.md
CP-3Contingency PlanningContingency Training
  • NIST 800-53
PlannedTraining record (planned)
CP-4Contingency PlanningContingency Plan Testing
  • NIST 800-53
  • SOC 2
Partialworker/src/maintenance.ts (runVerify); worker/RUNBOOK-restore.md
CP-6Contingency PlanningAlternate Storage Site
  • NIST 800-53
  • SOC 2
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
CP-7Contingency PlanningAlternate Processing Site
  • NIST 800-53
  • SOC 2
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
CP-8Contingency PlanningTelecommunications Services
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
CP-9Contingency PlanningSystem Backup
  • NIST 800-53
  • SOC 2
Partialworker/src/maintenance.ts; worker/wrangler.jsonc (triggers, r2_buckets); /api/status
CP-10Contingency PlanningSystem Recovery and Reconstitution
  • NIST 800-53
  • SOC 2
Partialworker/RUNBOOK-restore.md; controls/runbooks/contingency-plan.md (DRAFT)
IA-1Identification and AuthenticationPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/access-control.md (DRAFT)
IA-2Identification and AuthenticationIdentification and Authentication (Organizational Users)
  • NIST 800-53
  • SOC 2
Partialcontrols/evidence/2026-10-09-access-app.json; GitHub org 2FA setting (to capture)
IA-4Identification and AuthenticationIdentifier Management
  • NIST 800-53
  • SOC 2
Partialcontrols/policies/access-control.md (DRAFT)
IA-5Identification and AuthenticationAuthenticator Management
  • NIST 800-53
  • SOC 2
PartialGitHub Actions secrets; rotation record (planned)
IA-6Identification and AuthenticationAuthentication Feedback
  • NIST 800-53
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04)
IA-7Identification and AuthenticationCryptographic Module Authentication
  • NIST 800-53
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04)
IA-11Identification and AuthenticationRe-authentication
  • NIST 800-53
PartialAccess session setting
IR-1Incident ResponsePolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/incident-response.md (DRAFT)
IR-2Incident ResponseIncident Response Training
  • NIST 800-53
Plannedcontrols/policies/incident-response.md (DRAFT)
IR-3Incident ResponseIncident Response Testing
  • NIST 800-53
Plannedcontrols/runbooks/tabletop-2026Q4.md
IR-4Incident ResponseIncident Handling
  • NIST 800-53
  • SOC 2
Partialcontrols/runbooks/incident-response.md (DRAFT); .github/workflows/scheduled-security.yml
IR-5Incident ResponseIncident Monitoring
  • NIST 800-53
  • SOC 2
PlannedObvera incident records (planned)
IR-6Incident ResponseIncident Reporting
  • NIST 800-53
  • SOC 2
PartialSECURITY.md
IR-7Incident ResponseIncident Response Assistance
  • NIST 800-53
Plannedcontrols/policies/incident-response.md (DRAFT)
IR-8Incident ResponseIncident Response Plan
  • NIST 800-53
  • SOC 2
Partialcontrols/runbooks/incident-response.md (DRAFT); controls/policies/incident-response.md (DRAFT)
MA-1MaintenancePolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/information-security.md (DRAFT)
MA-2MaintenanceControlled Maintenance
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
MA-3MaintenanceMaintenance Tools
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
MA-4MaintenanceNonlocal Maintenance
  • NIST 800-53
Partial.github/workflows/ci.yml
MA-5MaintenanceMaintenance Personnel
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
MA-6MaintenanceTimely Maintenance
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
MP-1Media ProtectionPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/data-retention-privacy.md (DRAFT)
MP-2Media ProtectionMedia Access
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
MP-3Media ProtectionMedia Marking
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
MP-4Media ProtectionMedia Storage
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
MP-5Media ProtectionMedia Transport
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
MP-6Media ProtectionMedia Sanitization
  • NIST 800-53
  • SOC 2
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
MP-7Media ProtectionMedia Use
  • NIST 800-53
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PE-1Physical and Environmental ProtectionPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/information-security.md (DRAFT)
PE-2Physical and Environmental ProtectionPhysical Access Authorizations
  • NIST 800-53
  • SOC 2
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-3Physical and Environmental ProtectionPhysical Access Control
  • NIST 800-53
  • SOC 2
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-4Physical and Environmental ProtectionAccess Control for Transmission
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-5Physical and Environmental ProtectionAccess Control for Output Devices
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-6Physical and Environmental ProtectionMonitoring Physical Access
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-8Physical and Environmental ProtectionVisitor Access Records
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-9Physical and Environmental ProtectionPower Equipment and Cabling
  • NIST 800-53
  • SOC 2
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-10Physical and Environmental ProtectionEmergency Shutoff
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-11Physical and Environmental ProtectionEmergency Power
  • NIST 800-53
  • SOC 2
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-12Physical and Environmental ProtectionEmergency Lighting
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-13Physical and Environmental ProtectionFire Protection
  • NIST 800-53
  • SOC 2
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-14Physical and Environmental ProtectionEnvironmental Controls
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-15Physical and Environmental ProtectionWater Damage Protection
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-16Physical and Environmental ProtectionDelivery and Removal
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
PE-17Physical and Environmental ProtectionAlternate Work Site
  • NIST 800-53
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PL-1PlanningPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/information-security.md (DRAFT)
PL-2PlanningSystem Security and Privacy Plans
  • NIST 800-53
  • SOC 2
Partialcontrols/
PL-4PlanningRules of Behavior
  • NIST 800-53
  • SOC 2
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PL-8PlanningSecurity and Privacy Architectures
  • NIST 800-53
PartialBRIEF.md
PL-10PlanningBaseline Selection
  • NIST 800-53
  • SOC 2
Implementedcontrols/nist-800-53-moderate.csv
PL-11PlanningBaseline Tailoring
  • NIST 800-53
  • SOC 2
Implementedcontrols/nist-800-53-moderate.csv
PS-1Personnel SecurityPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PS-2Personnel SecurityPosition Risk Designation
  • NIST 800-53
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PS-3Personnel SecurityPersonnel Screening
  • NIST 800-53
  • SOC 2
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PS-4Personnel SecurityPersonnel Termination
  • NIST 800-53
  • SOC 2
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PS-5Personnel SecurityPersonnel Transfer
  • NIST 800-53
  • SOC 2
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PS-6Personnel SecurityAccess Agreements
  • NIST 800-53
  • SOC 2
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PS-7Personnel SecurityExternal Personnel Security
  • NIST 800-53
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PS-8Personnel SecurityPersonnel Sanctions
  • NIST 800-53
  • SOC 2
Plannedcontrols/policies/acceptable-use.md (DRAFT)
PS-9Personnel SecurityPosition Descriptions
  • NIST 800-53
  • SOC 2
Plannedcontrols/policies/acceptable-use.md (DRAFT)
RA-1Risk AssessmentPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/vulnerability-management.md (DRAFT)
RA-2Risk AssessmentSecurity Categorization
  • NIST 800-53
  • SOC 2
Plannedcontrols/policies/data-retention-privacy.md (DRAFT)
RA-3Risk AssessmentRisk Assessment
  • NIST 800-53
  • SOC 2
Plannedcontrols/GAPS.md
RA-5Risk AssessmentVulnerability Monitoring and Scanning
  • NIST 800-53
  • SOC 2
Implemented.github/workflows/ci.yml; .github/workflows/scheduled-security.yml; .github/dependabot.yml; controls/evidence/2026-10-09-github-protections.json
RA-7Risk AssessmentRisk Response
  • NIST 800-53
  • SOC 2
Partialcontrols/GAPS.md
RA-9Risk AssessmentCriticality Analysis
  • NIST 800-53
Plannedcontrols/GAPS.md
SA-1System and Services AcquisitionPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/change-management.md (DRAFT)
SA-2System and Services AcquisitionAllocation of Resources
  • NIST 800-53
Partialcontrols/GAPS.md
SA-3System and Services AcquisitionSystem Development Life Cycle
  • NIST 800-53
  • SOC 2
Partialcontrols/policies/change-management.md (DRAFT); .github/workflows/ci.yml
SA-4System and Services AcquisitionAcquisition Process
  • NIST 800-53
Plannedcontrols/policies/vendor-management.md (DRAFT)
SA-5System and Services AcquisitionSystem Documentation
  • NIST 800-53
  • SOC 2
PartialREADME.md; BRIEF.md; controls/
SA-8System and Services AcquisitionSecurity and Privacy Engineering Principles
  • NIST 800-53
Partialcontrols/stig-cis-web.md
SA-9System and Services AcquisitionExternal System Services
  • NIST 800-53
  • SOC 2
Partialcontrols/policies/vendor-management.md (DRAFT)
SA-10System and Services AcquisitionDeveloper Configuration Management
  • NIST 800-53
  • SOC 2
Implementedcontrols/evidence/2026-10-09-github-protections.json; .github/CODEOWNERS; .github/workflows/ci.yml
SA-11System and Services AcquisitionDeveloper Testing and Evaluation
  • NIST 800-53
Implemented.github/workflows/ci.yml
SA-15System and Services AcquisitionDevelopment Process, Standards, and Tools
  • NIST 800-53
Partial.github/workflows/ci.yml
SA-22System and Services AcquisitionUnsupported System Components
  • NIST 800-53
Partial.github/dependabot.yml; .github/workflows/ci.yml
SC-1System and Communications ProtectionPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/information-security.md (DRAFT)
SC-2System and Communications ProtectionSeparation of System and User Functionality
  • NIST 800-53
Partialworker/ (not in this branch)
SC-4System and Communications ProtectionInformation in Shared System Resources
  • NIST 800-53
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04)
SC-5System and Communications ProtectionDenial-of-Service Protection
  • NIST 800-53
  • SOC 2
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04); worker/ (not in this branch)
SC-7System and Communications ProtectionBoundary Protection
  • NIST 800-53
  • SOC 2
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04)
SC-8System and Communications ProtectionTransmission Confidentiality and Integrity
  • NIST 800-53
  • SOC 2
Implementedscripts/check-headers.sh; scripts/check-tls.sh; controls/evidence/2026-10-09-cloudflare-baseline.json
SC-10System and Communications ProtectionNetwork Disconnect
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
SC-12System and Communications ProtectionCryptographic Key Establishment and Management
  • NIST 800-53
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04)
SC-13System and Communications ProtectionCryptographic Protection
  • NIST 800-53
  • SOC 2
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04)
SC-17System and Communications ProtectionPublic Key Infrastructure Certificates
  • NIST 800-53
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04)
SC-18System and Communications ProtectionMobile Code
  • NIST 800-53
Implementedworker/src/security.ts; scripts/check-headers.sh
SC-20System and Communications ProtectionSecure Name/Address Resolution Service (Authoritative Source)
  • NIST 800-53
Partialcontrols/evidence/2026-10-09-cloudflare-baseline.json
SC-21System and Communications ProtectionSecure Name/Address Resolution Service (Recursive or Caching Resolver)
  • NIST 800-53
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)
SC-22System and Communications ProtectionArchitecture and Provisioning for Name/Address Resolution Service
  • NIST 800-53
PartialDomain inventory pipeline
SC-23System and Communications ProtectionSession Authenticity
  • NIST 800-53
Partialworker/ tests (not in this branch)
SC-28System and Communications ProtectionProtection of Information at Rest
  • NIST 800-53
  • SOC 2
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04); worker/wrangler.jsonc
SC-39System and Communications ProtectionProcess Isolation
  • NIST 800-53
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04)
SI-1System and Information IntegrityPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/vulnerability-management.md (DRAFT)
SI-2System and Information IntegrityFlaw Remediation
  • NIST 800-53
  • SOC 2
Implemented.github/dependabot.yml; .github/workflows/ci.yml
SI-3System and Information IntegrityMalicious Code Protection
  • NIST 800-53
  • SOC 2
Partial.github/workflows/ci.yml
SI-4System and Information IntegritySystem Monitoring
  • NIST 800-53
  • SOC 2
Partialworker/wrangler.jsonc (observability); worker/src/public.ts (/status); worker/src/auditchain.ts
SI-5System and Information IntegritySecurity Alerts, Advisories, and Directives
  • NIST 800-53
Partial.github/dependabot.yml
SI-7System and Information IntegritySoftware, Firmware, and Information Integrity
  • NIST 800-53
  • SOC 2
Partial.github/workflows/ci.yml; worker/src/auditchain.ts; worker/src/maintenance.ts
SI-8System and Information IntegritySpam Protection
  • NIST 800-53
Implementedworker/src/public.ts; worker/src/security.ts; worker/test/api.test.ts
SI-10System and Information IntegrityInformation Input Validation
  • NIST 800-53
  • SOC 2
Implementedworker/src/public.ts; worker/test/api.test.ts; worker/test/hardening.test.ts
SI-11System and Information IntegrityError Handling
  • NIST 800-53
Partial.github/workflows/ci.yml (zap job)
SI-12System and Information IntegrityInformation Management and Retention
  • NIST 800-53
  • SOC 2
Partialworker/src/maintenance.ts; controls/policies/data-retention-privacy.md (DRAFT)
SI-16System and Information IntegrityMemory Protection
  • NIST 800-53
ImplementedCloudflare SOC 2 Type II report (obtain, GAPS G-04)
SR-1Supply Chain Risk ManagementPolicy and Procedures
  • NIST 800-53
Plannedcontrols/policies/vendor-management.md (DRAFT)
SR-2Supply Chain Risk ManagementSupply Chain Risk Management Plan
  • NIST 800-53
Plannedcontrols/policies/vendor-management.md (DRAFT)
SR-3Supply Chain Risk ManagementSupply Chain Controls and Processes
  • NIST 800-53
Partial.github/workflows/ci.yml; .github/dependabot.yml
SR-5Supply Chain Risk ManagementAcquisition Strategies, Tools, and Methods
  • NIST 800-53
Plannedcontrols/policies/vendor-management.md (DRAFT)
SR-6Supply Chain Risk ManagementSupplier Assessments and Reviews
  • NIST 800-53
  • SOC 2
Plannedcontrols/policies/vendor-management.md (DRAFT)
SR-8Supply Chain Risk ManagementNotification Agreements
  • NIST 800-53
  • SOC 2
Plannedcontrols/policies/vendor-management.md (DRAFT)
SR-10Supply Chain Risk ManagementInspection of Systems or Components
  • NIST 800-53
Plannedcontrols/policies/vendor-management.md (DRAFT)
SR-11Supply Chain Risk ManagementComponent Authenticity
  • NIST 800-53
Partialpackage-lock.json
SR-12Supply Chain Risk ManagementComponent Disposal
  • NIST 800-53
  • SOC 2
PartialCloudflare SOC 2 Type II report (obtain, GAPS G-04)

Status key: Implemented means the control is in place and we hold the evidence listed. Partial means it is in place in part. Planned means it is not yet in place. None of these is an audit finding.