Control mapping
Each control we track, the frameworks it supports, how far along it is, and the evidence. This mapping is our own work and has not been independently audited. It is not a certification.
169 controls shown
| Control | Title | Frameworks | Status | Evidence |
|---|---|---|---|---|
| AC-1Access Control | Policy and Procedures |
| Planned | controls/policies/access-control.md (DRAFT) |
| AC-2Access Control | Account Management |
| Partial | controls/evidence/2026-10-09-access-app.json; GitHub org members; access review record (planned) |
| AC-3Access Control | Access Enforcement |
| Implemented | controls/evidence/2026-10-09-access-app.json; worker/src/admin.ts; worker/test/api.test.ts |
| AC-4Access Control | Information Flow Enforcement |
| Implemented | worker/src/security.ts; worker/src/public.ts (same-origin guard); scripts/check-headers.sh; .github/workflows/ci.yml (post-deploy header check) |
| AC-5Access Control | Separation of Duties |
| Partial | GitHub environment 'production' protection rule |
| AC-6Access Control | Least Privilege |
| Partial | .github/workflows/ci.yml (permissions block) |
| AC-7Access Control | Unsuccessful Logon Attempts |
| Partial | worker/wrangler.jsonc (ratelimits); worker/src/public.ts; worker/test/api.test.ts; controls/evidence/2026-10-09-access-app.json |
| AC-8Access Control | System Use Notification |
| Planned | Admin page banner (planned) |
| AC-11Access Control | Device Lock |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| AC-12Access Control | Session Termination |
| Implemented | controls/evidence/2026-10-09-access-app.json |
| AC-14Access Control | Permitted Actions Without Identification or Authentication |
| Implemented | controls/nist-800-53-moderate.csv; site map |
| AC-17Access Control | Remote Access |
| Partial | controls/evidence/2026-10-09-access-app.json; worker/src/admin.ts; .github/workflows/ci.yml (deploy job); GitHub org 2FA setting (to capture) |
| AC-20Access Control | Use of External Systems |
| Partial | controls/policies/vendor-management.md (DRAFT) |
| AC-21Access Control | Information Sharing |
| Partial | privacy.html; controls/policies/data-retention-privacy.md (DRAFT) |
| AC-22Access Control | Publicly Accessible Content |
| Implemented | controls/evidence/2026-10-09-github-protections.json; .github/CODEOWNERS; .github/workflows/ci.yml; scripts/apply-github-protections.sh |
| AT-1Awareness and Training | Policy and Procedures |
| Planned | controls/policies/information-security.md (DRAFT) |
| AT-2Awareness and Training | Literacy Training and Awareness |
| Planned | Training record (planned) |
| AT-3Awareness and Training | Role-Based Training |
| Planned | Training record (planned) |
| AT-4Awareness and Training | Training Records |
| Planned | Training record (planned) |
| AU-1Audit and Accountability | Policy and Procedures |
| Planned | controls/policies/information-security.md (DRAFT) |
| AU-2Audit and Accountability | Event Logging |
| Implemented | worker/src/auditchain.ts; worker/src/maintenance.ts; worker/test/hardening.test.ts |
| AU-3Audit and Accountability | Content of Audit Records |
| Implemented | worker/migrations/0001_init.sql; worker/migrations/0002_audit_hash_chain.sql; worker/src/auditchain.ts |
| AU-4Audit and Accountability | Audit Log Storage Capacity |
| Partial | D1 usage dashboard |
| AU-5Audit and Accountability | Response to Audit Logging Process Failures |
| Planned | Alert rule (planned) |
| AU-6Audit and Accountability | Audit Record Review, Analysis, and Reporting |
| Planned | Audit review record (planned) |
| AU-7Audit and Accountability | Audit Record Reduction and Report Generation |
| Planned | Saved D1 queries (planned) |
| AU-8Audit and Accountability | Time Stamps |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| AU-9Audit and Accountability | Protection of Audit Information |
| Partial | worker/src/auditchain.ts (verifyChain); worker/src/maintenance.ts; worker/test/hardening.test.ts |
| AU-11Audit and Accountability | Audit Record Retention |
| Partial | worker/src/maintenance.ts (RETENTION_DAYS, KEEP_BACKUPS); controls/policies/data-retention-privacy.md (DRAFT) |
| AU-12Audit and Accountability | Audit Record Generation |
| Implemented | worker/src/auditchain.ts; worker/src/public.ts; worker/test/hardening.test.ts |
| CA-1Assessment, Authorization, and Monitoring | Policy and Procedures |
| Planned | controls/policies/information-security.md (DRAFT) |
| CA-2Assessment, Authorization, and Monitoring | Control Assessments |
| Partial | .github/workflows/ci.yml |
| CA-3Assessment, Authorization, and Monitoring | Information Exchange |
| Partial | controls/vendor-register.md (DRAFT); controls/inventory.md (DRAFT) |
| CA-5Assessment, Authorization, and Monitoring | Plan of Action and Milestones |
| Partial | controls/GAPS.md |
| CA-6Assessment, Authorization, and Monitoring | Authorization |
| Planned | Authorization memo (planned) |
| CA-7Assessment, Authorization, and Monitoring | Continuous Monitoring |
| Implemented | .github/workflows/scheduled-security.yml; .github/workflows/ci.yml |
| CA-9Assessment, Authorization, and Monitoring | Internal System Connections |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| CM-1Configuration Management | Policy and Procedures |
| Planned | controls/policies/change-management.md (DRAFT) |
| CM-2Configuration Management | Baseline Configuration |
| Implemented | wrangler config; .github/workflows/ci.yml |
| CM-3Configuration Management | Configuration Change Control |
| Implemented | controls/evidence/2026-10-09-github-protections.json; .github/pull_request_template.md; .github/workflows/ci.yml; scripts/apply-github-protections.sh |
| CM-4Configuration Management | Impact Analyses |
| Partial | .github/pull_request_template.md |
| CM-5Configuration Management | Access Restrictions for Change |
| Partial | controls/evidence/2026-10-09-github-protections.json; .github/CODEOWNERS |
| CM-6Configuration Management | Configuration Settings |
| Implemented | scripts/check-headers.sh; scripts/check-cloudflare-baseline.sh; controls/evidence/2026-10-09-cloudflare-baseline.json |
| CM-7Configuration Management | Least Functionality |
| Implemented | worker/src/index.ts; worker/src/security.ts; worker/test/hardening.test.ts |
| CM-8Configuration Management | System Component Inventory |
| Partial | controls/inventory.md (DRAFT); .github/workflows/ci.yml (sbom job) |
| CM-9Configuration Management | Configuration Management Plan |
| Planned | controls/policies/change-management.md (DRAFT) |
| CM-10Configuration Management | Software Usage Restrictions |
| Planned | License check (planned) |
| CP-1Contingency Planning | Policy and Procedures |
| Planned | controls/policies/incident-response.md (DRAFT) |
| CP-2Contingency Planning | Contingency Plan |
| Partial | controls/runbooks/contingency-plan.md (DRAFT); worker/RUNBOOK-restore.md |
| CP-3Contingency Planning | Contingency Training |
| Planned | Training record (planned) |
| CP-4Contingency Planning | Contingency Plan Testing |
| Partial | worker/src/maintenance.ts (runVerify); worker/RUNBOOK-restore.md |
| CP-6Contingency Planning | Alternate Storage Site |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| CP-7Contingency Planning | Alternate Processing Site |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| CP-8Contingency Planning | Telecommunications Services |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| CP-9Contingency Planning | System Backup |
| Partial | worker/src/maintenance.ts; worker/wrangler.jsonc (triggers, r2_buckets); /api/status |
| CP-10Contingency Planning | System Recovery and Reconstitution |
| Partial | worker/RUNBOOK-restore.md; controls/runbooks/contingency-plan.md (DRAFT) |
| IA-1Identification and Authentication | Policy and Procedures |
| Planned | controls/policies/access-control.md (DRAFT) |
| IA-2Identification and Authentication | Identification and Authentication (Organizational Users) |
| Partial | controls/evidence/2026-10-09-access-app.json; GitHub org 2FA setting (to capture) |
| IA-4Identification and Authentication | Identifier Management |
| Partial | controls/policies/access-control.md (DRAFT) |
| IA-5Identification and Authentication | Authenticator Management |
| Partial | GitHub Actions secrets; rotation record (planned) |
| IA-6Identification and Authentication | Authentication Feedback |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| IA-7Identification and Authentication | Cryptographic Module Authentication |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| IA-11Identification and Authentication | Re-authentication |
| Partial | Access session setting |
| IR-1Incident Response | Policy and Procedures |
| Planned | controls/policies/incident-response.md (DRAFT) |
| IR-2Incident Response | Incident Response Training |
| Planned | controls/policies/incident-response.md (DRAFT) |
| IR-3Incident Response | Incident Response Testing |
| Planned | controls/runbooks/tabletop-2026Q4.md |
| IR-4Incident Response | Incident Handling |
| Partial | controls/runbooks/incident-response.md (DRAFT); .github/workflows/scheduled-security.yml |
| IR-5Incident Response | Incident Monitoring |
| Planned | Obvera incident records (planned) |
| IR-6Incident Response | Incident Reporting |
| Partial | SECURITY.md |
| IR-7Incident Response | Incident Response Assistance |
| Planned | controls/policies/incident-response.md (DRAFT) |
| IR-8Incident Response | Incident Response Plan |
| Partial | controls/runbooks/incident-response.md (DRAFT); controls/policies/incident-response.md (DRAFT) |
| MA-1Maintenance | Policy and Procedures |
| Planned | controls/policies/information-security.md (DRAFT) |
| MA-2Maintenance | Controlled Maintenance |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| MA-3Maintenance | Maintenance Tools |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| MA-4Maintenance | Nonlocal Maintenance |
| Partial | .github/workflows/ci.yml |
| MA-5Maintenance | Maintenance Personnel |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| MA-6Maintenance | Timely Maintenance |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| MP-1Media Protection | Policy and Procedures |
| Planned | controls/policies/data-retention-privacy.md (DRAFT) |
| MP-2Media Protection | Media Access |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| MP-3Media Protection | Media Marking |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| MP-4Media Protection | Media Storage |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| MP-5Media Protection | Media Transport |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| MP-6Media Protection | Media Sanitization |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| MP-7Media Protection | Media Use |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PE-1Physical and Environmental Protection | Policy and Procedures |
| Planned | controls/policies/information-security.md (DRAFT) |
| PE-2Physical and Environmental Protection | Physical Access Authorizations |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-3Physical and Environmental Protection | Physical Access Control |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-4Physical and Environmental Protection | Access Control for Transmission |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-5Physical and Environmental Protection | Access Control for Output Devices |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-6Physical and Environmental Protection | Monitoring Physical Access |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-8Physical and Environmental Protection | Visitor Access Records |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-9Physical and Environmental Protection | Power Equipment and Cabling |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-10Physical and Environmental Protection | Emergency Shutoff |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-11Physical and Environmental Protection | Emergency Power |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-12Physical and Environmental Protection | Emergency Lighting |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-13Physical and Environmental Protection | Fire Protection |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-14Physical and Environmental Protection | Environmental Controls |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-15Physical and Environmental Protection | Water Damage Protection |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-16Physical and Environmental Protection | Delivery and Removal |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| PE-17Physical and Environmental Protection | Alternate Work Site |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PL-1Planning | Policy and Procedures |
| Planned | controls/policies/information-security.md (DRAFT) |
| PL-2Planning | System Security and Privacy Plans |
| Partial | controls/ |
| PL-4Planning | Rules of Behavior |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PL-8Planning | Security and Privacy Architectures |
| Partial | BRIEF.md |
| PL-10Planning | Baseline Selection |
| Implemented | controls/nist-800-53-moderate.csv |
| PL-11Planning | Baseline Tailoring |
| Implemented | controls/nist-800-53-moderate.csv |
| PS-1Personnel Security | Policy and Procedures |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PS-2Personnel Security | Position Risk Designation |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PS-3Personnel Security | Personnel Screening |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PS-4Personnel Security | Personnel Termination |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PS-5Personnel Security | Personnel Transfer |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PS-6Personnel Security | Access Agreements |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PS-7Personnel Security | External Personnel Security |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PS-8Personnel Security | Personnel Sanctions |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| PS-9Personnel Security | Position Descriptions |
| Planned | controls/policies/acceptable-use.md (DRAFT) |
| RA-1Risk Assessment | Policy and Procedures |
| Planned | controls/policies/vulnerability-management.md (DRAFT) |
| RA-2Risk Assessment | Security Categorization |
| Planned | controls/policies/data-retention-privacy.md (DRAFT) |
| RA-3Risk Assessment | Risk Assessment |
| Planned | controls/GAPS.md |
| RA-5Risk Assessment | Vulnerability Monitoring and Scanning |
| Implemented | .github/workflows/ci.yml; .github/workflows/scheduled-security.yml; .github/dependabot.yml; controls/evidence/2026-10-09-github-protections.json |
| RA-7Risk Assessment | Risk Response |
| Partial | controls/GAPS.md |
| RA-9Risk Assessment | Criticality Analysis |
| Planned | controls/GAPS.md |
| SA-1System and Services Acquisition | Policy and Procedures |
| Planned | controls/policies/change-management.md (DRAFT) |
| SA-2System and Services Acquisition | Allocation of Resources |
| Partial | controls/GAPS.md |
| SA-3System and Services Acquisition | System Development Life Cycle |
| Partial | controls/policies/change-management.md (DRAFT); .github/workflows/ci.yml |
| SA-4System and Services Acquisition | Acquisition Process |
| Planned | controls/policies/vendor-management.md (DRAFT) |
| SA-5System and Services Acquisition | System Documentation |
| Partial | README.md; BRIEF.md; controls/ |
| SA-8System and Services Acquisition | Security and Privacy Engineering Principles |
| Partial | controls/stig-cis-web.md |
| SA-9System and Services Acquisition | External System Services |
| Partial | controls/policies/vendor-management.md (DRAFT) |
| SA-10System and Services Acquisition | Developer Configuration Management |
| Implemented | controls/evidence/2026-10-09-github-protections.json; .github/CODEOWNERS; .github/workflows/ci.yml |
| SA-11System and Services Acquisition | Developer Testing and Evaluation |
| Implemented | .github/workflows/ci.yml |
| SA-15System and Services Acquisition | Development Process, Standards, and Tools |
| Partial | .github/workflows/ci.yml |
| SA-22System and Services Acquisition | Unsupported System Components |
| Partial | .github/dependabot.yml; .github/workflows/ci.yml |
| SC-1System and Communications Protection | Policy and Procedures |
| Planned | controls/policies/information-security.md (DRAFT) |
| SC-2System and Communications Protection | Separation of System and User Functionality |
| Partial | worker/ (not in this branch) |
| SC-4System and Communications Protection | Information in Shared System Resources |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| SC-5System and Communications Protection | Denial-of-Service Protection |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04); worker/ (not in this branch) |
| SC-7System and Communications Protection | Boundary Protection |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| SC-8System and Communications Protection | Transmission Confidentiality and Integrity |
| Implemented | scripts/check-headers.sh; scripts/check-tls.sh; controls/evidence/2026-10-09-cloudflare-baseline.json |
| SC-10System and Communications Protection | Network Disconnect |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| SC-12System and Communications Protection | Cryptographic Key Establishment and Management |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| SC-13System and Communications Protection | Cryptographic Protection |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| SC-17System and Communications Protection | Public Key Infrastructure Certificates |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| SC-18System and Communications Protection | Mobile Code |
| Implemented | worker/src/security.ts; scripts/check-headers.sh |
| SC-20System and Communications Protection | Secure Name/Address Resolution Service (Authoritative Source) |
| Partial | controls/evidence/2026-10-09-cloudflare-baseline.json |
| SC-21System and Communications Protection | Secure Name/Address Resolution Service (Recursive or Caching Resolver) |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| SC-22System and Communications Protection | Architecture and Provisioning for Name/Address Resolution Service |
| Partial | Domain inventory pipeline |
| SC-23System and Communications Protection | Session Authenticity |
| Partial | worker/ tests (not in this branch) |
| SC-28System and Communications Protection | Protection of Information at Rest |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04); worker/wrangler.jsonc |
| SC-39System and Communications Protection | Process Isolation |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| SI-1System and Information Integrity | Policy and Procedures |
| Planned | controls/policies/vulnerability-management.md (DRAFT) |
| SI-2System and Information Integrity | Flaw Remediation |
| Implemented | .github/dependabot.yml; .github/workflows/ci.yml |
| SI-3System and Information Integrity | Malicious Code Protection |
| Partial | .github/workflows/ci.yml |
| SI-4System and Information Integrity | System Monitoring |
| Partial | worker/wrangler.jsonc (observability); worker/src/public.ts (/status); worker/src/auditchain.ts |
| SI-5System and Information Integrity | Security Alerts, Advisories, and Directives |
| Partial | .github/dependabot.yml |
| SI-7System and Information Integrity | Software, Firmware, and Information Integrity |
| Partial | .github/workflows/ci.yml; worker/src/auditchain.ts; worker/src/maintenance.ts |
| SI-8System and Information Integrity | Spam Protection |
| Implemented | worker/src/public.ts; worker/src/security.ts; worker/test/api.test.ts |
| SI-10System and Information Integrity | Information Input Validation |
| Implemented | worker/src/public.ts; worker/test/api.test.ts; worker/test/hardening.test.ts |
| SI-11System and Information Integrity | Error Handling |
| Partial | .github/workflows/ci.yml (zap job) |
| SI-12System and Information Integrity | Information Management and Retention |
| Partial | worker/src/maintenance.ts; controls/policies/data-retention-privacy.md (DRAFT) |
| SI-16System and Information Integrity | Memory Protection |
| Implemented | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
| SR-1Supply Chain Risk Management | Policy and Procedures |
| Planned | controls/policies/vendor-management.md (DRAFT) |
| SR-2Supply Chain Risk Management | Supply Chain Risk Management Plan |
| Planned | controls/policies/vendor-management.md (DRAFT) |
| SR-3Supply Chain Risk Management | Supply Chain Controls and Processes |
| Partial | .github/workflows/ci.yml; .github/dependabot.yml |
| SR-5Supply Chain Risk Management | Acquisition Strategies, Tools, and Methods |
| Planned | controls/policies/vendor-management.md (DRAFT) |
| SR-6Supply Chain Risk Management | Supplier Assessments and Reviews |
| Planned | controls/policies/vendor-management.md (DRAFT) |
| SR-8Supply Chain Risk Management | Notification Agreements |
| Planned | controls/policies/vendor-management.md (DRAFT) |
| SR-10Supply Chain Risk Management | Inspection of Systems or Components |
| Planned | controls/policies/vendor-management.md (DRAFT) |
| SR-11Supply Chain Risk Management | Component Authenticity |
| Partial | package-lock.json |
| SR-12Supply Chain Risk Management | Component Disposal |
| Partial | Cloudflare SOC 2 Type II report (obtain, GAPS G-04) |
No controls match those filters.
Status key: Implemented means the control is in place and we hold the evidence listed. Partial means it is in place in part. Planned means it is not yet in place. None of these is an audit finding.