Implementation
What code, configuration or procedures exist for each requirement, including unfinished work.
NIST CSF 2.0
Guided by NIST Cybersecurity Framework (CSF) 2.0. This page shows the status of 23 selected requirements for Military OS, what has been checked and what remains.
Evidence snapshot Internal review · Shared product and operating practices
Current evidence covers shared product development and local testing. Hosted reference/demo verification and client launch checks have not yet been assessed.
Product controls
Current local checks use synthetic test records, simulated external services, isolated local databases, selected configuration profiles and selected local demo-organization checks. They do not establish behavior with customer records or in a customer's operating environment.
A future hosted representative demo can use synthetic data to check real MFA, TLS, alert delivery and recovery without customer records. Any live-verified result on this page would apply only to that named hosted reference/demo boundary.
Shared-code evidence is reusable only for the tested release, configuration and cases exercised. Separate client launch checks confirm enabled settings, integrations and installation conformity with synthetic accounts; they do not require a full reassessment using customer data.
Military OS uses one maintained product, configured and deployed separately for each association. Record the product release and configuration assessed for each installation. Changes affecting security controls require review and testing.
Current snapshot
23 selected requirements · 0 live verified
What code, configuration or procedures exist for each requirement, including unfinished work.
Which checks passed and their limits. A passing check covers the stated cases, not the entire security requirement.
Not yet assessed. A representative hosted demo can verify real integrations with synthetic data before separate client launch checks.
The evidence table separates these stages. The overall ratings below retain the original assessment: a requirement can remain partial while several local checks have passed.
3 total · 1 no reviewed evidence, 2 partial
2 total · 1 no reviewed evidence, 1 partial
13 total · 1 no reviewed evidence, 9 partial, 1 implemented, 2 locally tested
2 total · 2 partial
1 total · 1 no reviewed evidence
2 total · 2 partial
A partial requirement can contain several passing tests. Its status remains partial until the full stated requirement is supported. Local tests do not establish hosted reference/demo operation.
Review the scope
Open a function to review its requirements. On smaller screens, scroll tables horizontally to read all columns.
Requirement IDs are Military OS tracking labels, not NIST subcategory numbers. Dates identify the evidence review for each row; this page does not monitor installations automatically.
| Requirement | Implementation | Local verification | Hosted reference/demo verification | Remaining work | Reviewed |
|---|---|---|---|---|---|
| GV-01Supported information and service scopeOverall requirementPartial | Product information and operating scope documented. | Not yet assessed through a completed client intake. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Confirm each customer's information and contractual requirements before launch. | |
| GV-02Security responsibilities and reviewsOverall requirementNo reviewed evidence | No completed ownership and review record evidenced. | Not yet assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Document accountable owners, review dates and risk decisions. | |
| GV-03Suppliers and shared responsibilitiesOverall requirementPartial | Connected services and their roles documented; responsibility review incomplete. | Not yet assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Complete the supplier, support-access and data-responsibility review. |
| Requirement | Implementation | Local verification | Hosted reference/demo verification | Remaining work | Reviewed |
|---|---|---|---|---|---|
| ID-01System and data inventoryOverall requirementPartial | Architecture and data definitions documented; installation inventory incomplete. | Not yet assessed as a complete inventory. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Complete the inventory for each installation and its operating accounts. | |
| ID-02Threat and vulnerability reviewOverall requirementNo reviewed evidence | No completed threat and vulnerability assessment evidenced. | Not yet assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Record the assessment, remediation priorities and review process. |
| Requirement | Implementation | Local verification | Hosted reference/demo verification | Remaining work | Reviewed |
|---|---|---|---|---|---|
| PR-01Identity checks at sign-inOverall requirementLocally tested | Sign-in boundary and deployed-mode authentication guards implemented. | Passed: selected identity-boundary tests with simulated identity-provider calls. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Verify real enrollment, callbacks and sign-out before launch. | |
| PR-02Multi-factor authenticationOverall requirementPartial | Required authenticator-app MFA configured for all password accounts. | Passed: configuration assertions across representative profiles. Real enrollment and recovery not tested. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Verify live enrollment and recovery, plus separate operator-account MFA. | |
| PR-03Role and record permissionsOverall requirementPartial | Server role and record permissions implemented in reviewed routes. | Passed: selected denied-access cases. Full privileged-route coverage not assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Complete coverage across privileged workflows and record scopes. | |
| PR-04Account blocking and access removalOverall requirementPartial | Session expiry, revocation, account blocking and permission refresh implemented. | Passed: unit and isolated database checks of session and account access. Offboarding reviews remain outstanding. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Verify complete account removal and periodic access reviews in operation. | |
| PR-05Encrypted database connection settingsOverall requirementLocally tested | Certificate verification required by deployed database connection settings. | Passed: configuration rejection tests and force-encryption template checks. Actual TLS connections not tested. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Test actual encrypted connections and certificate rejection before launch. | |
| PR-06Stored data protectionOverall requirementImplemented | Database encryption and separate public/private storage policies configured. | Passed: database-encryption template assertion. Complete storage-policy behavior not assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Complete policy checks and verify the created storage and key access. | |
| PR-07Service credentials and recoveryOverall requirementPartial | Service-database credential recovery procedure implemented; other secret procedures incomplete. | Passed: password-authenticated database exercises for rotation, login blocking, disconnection and recovery. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Complete other secret-rotation procedures and verify consumer updates in a live installation. | |
| PR-08Separate application and operator accessOverall requirementPartial | Restricted application database role and separate fixed-maintenance account implemented. | Passed: isolated database permission checks; local demo role and maintenance checks. AWS isolation not tested. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Verify installation isolation, deployed credentials and infrastructure permissions. | |
| PR-09Browser requests and input handlingOverall requirementPartial | Request-origin checks, input limits, headers and image handling implemented in reviewed areas. | Passed: selected request and upload checks. Complete route and abuse coverage not assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Extend coverage across routes and verify the live request boundary. | |
| PR-10Code checks and release processOverall requirementPartial | Automated code checks configured; operating release procedures incomplete. | Passed: lint, type and automated behavior checks on reviewed changes. Repository protections not assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Verify repository protections and document patch, release and rollback procedures. | |
| PR-11Operator devices and accountsOverall requirementNo reviewed evidence | Device and operator-account settings outside the repository assessment. | Not yet assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Verify device protections, account access and staff procedures privately. | |
| PR-12Personal data handlingOverall requirementPartial | Public-field, export and data-lifecycle rules implemented in reviewed areas. | Passed: selected data-handling tests. Complete operational retention and erasure not assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Complete operational retention, erasure and support-data procedures. | |
| PR-13Verified payment processingOverall requirementPartial | Provider-result validation and paid issuance rules implemented. | Passed: selected payment and issuance checks with simulated provider interactions. Actual callbacks not tested. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Verify actual provider callbacks and failed-event recovery before launch. |
| Requirement | Implementation | Local verification | Hosted reference/demo verification | Remaining work | Reviewed |
|---|---|---|---|---|---|
| DE-01Administrative audit recordsOverall requirementPartial | Restricted audit access and fixed retention maintenance implemented. | Passed: database checks for audit permissions, retention and award-linked evidence. Full event coverage not assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Review event coverage and verify live scheduling and retention expectations. | |
| DE-02Monitoring and alert responseOverall requirementPartial | Database and maintenance monitoring configured; alert response incomplete. | Not yet assessed through an alert-delivery and response exercise. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Verify alert delivery, ownership and response procedures in operation. |
| Requirement | Implementation | Local verification | Hosted reference/demo verification | Remaining work | Reviewed |
|---|---|---|---|---|---|
| RS-01Incident responseOverall requirementNo reviewed evidence | No completed security incident procedure and exercise evidenced. | Not yet assessed. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Complete the incident procedure and a recorded practice exercise. |
| Requirement | Implementation | Local verification | Hosted reference/demo verification | Remaining work | Reviewed |
|---|---|---|---|---|---|
| RC-01Backup coverage and recovery targetsOverall requirementPartial | Local restore procedure and infrastructure protection settings prepared; recovery targets incomplete. | Backup coverage and recovery targets not yet assessed. See the separate data-restoration exercise below. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Agree data-loss and recovery-time targets and verify backup coverage. | |
| RC-02Data restorationOverall requirementPartial | Repeatable local database restoration procedure implemented. | Passed: isolated restore with synthetic records and integrity checks. Realistic volumes and application recovery not tested. | Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate. | Verify realistic data volumes, application recovery and live restoration. |
Dated work
The timeline records completed work. It is not a security score. A numerical trend needs repeated reviews of the same requirements; the first snapshot starts that record.
Selected requirements were organized under the six NIST CSF functions, with evidence limits and remaining work.
A synthetic backup was restored and checked for data and relational integrity.
Local checks covered required MFA configuration, session revocation, account blocking and restricted application database access.
Local tests verified fixed maintenance permissions and retention of award-linked evidence.
Password-authenticated local tests verified rotation, login blocking, connection termination and recovery.
| Reviewed | Scope | Requirements | No reviewed evidence | Partial | Implemented | Locally tested | Live verified |
|---|---|---|---|---|---|---|---|
| selected-baseline-v1 | 23 | 4 | 16 | 1 | 2 | 0 |
Before each installation goes live
Confirm enabled settings, integrations and installation conformity with synthetic accounts. Changes from the assessed product release or configuration require review and testing of the affected controls. These checks do not require a full reassessment using customer data.
Read the account access and audit protections update for the recent product changes.
Discuss your installation