Implementation enquiries are openReview the maintained product and separate deployment model. Implementation and deployment

NIST CSF 2.0

Security progress

Guided by NIST Cybersecurity Framework (CSF) 2.0. This page shows the status of 23 selected requirements for Military OS, what has been checked and what remains.

Evidence snapshot Internal review · Shared product and operating practices

Current evidence covers shared product development and local testing. Hosted reference/demo verification and client launch checks have not yet been assessed.

Product controls

Security controls built into Military OS

  • Separate AWS resourcesEach association has its own application, database, identity, storage and configuration resources.
  • Controlled accessRole and record permissions restrict administrative routes and chapter-scoped records.
  • Administrative recordsSelected administrative actions are recorded with restricted audit access and retention controls.
  • Encrypted storage and connectionsHosted database connections require TLS and AWS-managed storage is encrypted at rest.
  • Backup and launch checksInfrastructure protection settings, restoration procedures and installation-specific launch checks are tracked separately.

What this evidence covers

Current local checks use synthetic test records, simulated external services, isolated local databases, selected configuration profiles and selected local demo-organization checks. They do not establish behavior with customer records or in a customer's operating environment.

A future hosted representative demo can use synthetic data to check real MFA, TLS, alert delivery and recovery without customer records. Any live-verified result on this page would apply only to that named hosted reference/demo boundary.

Shared-code evidence is reusable only for the tested release, configuration and cases exercised. Separate client launch checks confirm enabled settings, integrations and installation conformity with synthetic accounts; they do not require a full reassessment using customer data.

Military OS uses one maintained product, configured and deployed separately for each association. Record the product release and configuration assessed for each installation. Changes affecting security controls require review and testing.

Current snapshot

Implementation and verification

23 selected requirements · 0 live verified

Implementation

What code, configuration or procedures exist for each requirement, including unfinished work.

Local verification

Which checks passed and their limits. A passing check covers the stated cases, not the entire security requirement.

Hosted reference/demo verification

Not yet assessed. A representative hosted demo can verify real integrations with synthetic data before separate client launch checks.

The evidence table separates these stages. The overall ratings below retain the original assessment: a requirement can remain partial while several local checks have passed.

Overall requirement ratings
No reviewed evidence
4No completed evidence was found in the review scope.
Partial
16Some work exists; part remains unfinished or unverified.
Implemented
1Code or configuration exists; the full behavior has not been verified.
Locally tested
2Local checks passed for the stated scope. This does not verify a live installation.
Live verified
0Evidence demonstrates operation in a specified hosted reference/demo environment.
Requirement counts by NIST CSF function
Govern

3 total · 1 no reviewed evidence, 2 partial

Identify

2 total · 1 no reviewed evidence, 1 partial

Protect

13 total · 1 no reviewed evidence, 9 partial, 1 implemented, 2 locally tested

Detect

2 total · 2 partial

Respond

1 total · 1 no reviewed evidence

Recover

2 total · 2 partial

A partial requirement can contain several passing tests. Its status remains partial until the full stated requirement is supported. Local tests do not establish hosted reference/demo operation.

Review the scope

Requirements and evidence

Open a function to review its requirements. On smaller screens, scroll tables horizontally to read all columns.

Requirement IDs are Military OS tracking labels, not NIST subcategory numbers. Dates identify the evidence review for each row; this page does not monitor installations automatically.

Govern3 requirements
Govern: reviewed evidence and remaining work
RequirementImplementationLocal verificationHosted reference/demo verificationRemaining workReviewed
GV-01Supported information and service scopeOverall requirementPartialProduct information and operating scope documented.Not yet assessed through a completed client intake.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Confirm each customer's information and contractual requirements before launch.
GV-02Security responsibilities and reviewsOverall requirementNo reviewed evidenceNo completed ownership and review record evidenced.Not yet assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Document accountable owners, review dates and risk decisions.
GV-03Suppliers and shared responsibilitiesOverall requirementPartialConnected services and their roles documented; responsibility review incomplete.Not yet assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Complete the supplier, support-access and data-responsibility review.
Identify2 requirements
Identify: reviewed evidence and remaining work
RequirementImplementationLocal verificationHosted reference/demo verificationRemaining workReviewed
ID-01System and data inventoryOverall requirementPartialArchitecture and data definitions documented; installation inventory incomplete.Not yet assessed as a complete inventory.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Complete the inventory for each installation and its operating accounts.
ID-02Threat and vulnerability reviewOverall requirementNo reviewed evidenceNo completed threat and vulnerability assessment evidenced.Not yet assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Record the assessment, remediation priorities and review process.
Protect13 requirements
Protect: reviewed evidence and remaining work
RequirementImplementationLocal verificationHosted reference/demo verificationRemaining workReviewed
PR-01Identity checks at sign-inOverall requirementLocally testedSign-in boundary and deployed-mode authentication guards implemented.Passed: selected identity-boundary tests with simulated identity-provider calls.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Verify real enrollment, callbacks and sign-out before launch.
PR-02Multi-factor authenticationOverall requirementPartialRequired authenticator-app MFA configured for all password accounts.Passed: configuration assertions across representative profiles. Real enrollment and recovery not tested.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Verify live enrollment and recovery, plus separate operator-account MFA.
PR-03Role and record permissionsOverall requirementPartialServer role and record permissions implemented in reviewed routes.Passed: selected denied-access cases. Full privileged-route coverage not assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Complete coverage across privileged workflows and record scopes.
PR-04Account blocking and access removalOverall requirementPartialSession expiry, revocation, account blocking and permission refresh implemented.Passed: unit and isolated database checks of session and account access. Offboarding reviews remain outstanding.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Verify complete account removal and periodic access reviews in operation.
PR-05Encrypted database connection settingsOverall requirementLocally testedCertificate verification required by deployed database connection settings.Passed: configuration rejection tests and force-encryption template checks. Actual TLS connections not tested.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Test actual encrypted connections and certificate rejection before launch.
PR-06Stored data protectionOverall requirementImplementedDatabase encryption and separate public/private storage policies configured.Passed: database-encryption template assertion. Complete storage-policy behavior not assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Complete policy checks and verify the created storage and key access.
PR-07Service credentials and recoveryOverall requirementPartialService-database credential recovery procedure implemented; other secret procedures incomplete.Passed: password-authenticated database exercises for rotation, login blocking, disconnection and recovery.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Complete other secret-rotation procedures and verify consumer updates in a live installation.
PR-08Separate application and operator accessOverall requirementPartialRestricted application database role and separate fixed-maintenance account implemented.Passed: isolated database permission checks; local demo role and maintenance checks. AWS isolation not tested.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Verify installation isolation, deployed credentials and infrastructure permissions.
PR-09Browser requests and input handlingOverall requirementPartialRequest-origin checks, input limits, headers and image handling implemented in reviewed areas.Passed: selected request and upload checks. Complete route and abuse coverage not assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Extend coverage across routes and verify the live request boundary.
PR-10Code checks and release processOverall requirementPartialAutomated code checks configured; operating release procedures incomplete.Passed: lint, type and automated behavior checks on reviewed changes. Repository protections not assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Verify repository protections and document patch, release and rollback procedures.
PR-11Operator devices and accountsOverall requirementNo reviewed evidenceDevice and operator-account settings outside the repository assessment.Not yet assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Verify device protections, account access and staff procedures privately.
PR-12Personal data handlingOverall requirementPartialPublic-field, export and data-lifecycle rules implemented in reviewed areas.Passed: selected data-handling tests. Complete operational retention and erasure not assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Complete operational retention, erasure and support-data procedures.
PR-13Verified payment processingOverall requirementPartialProvider-result validation and paid issuance rules implemented.Passed: selected payment and issuance checks with simulated provider interactions. Actual callbacks not tested.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Verify actual provider callbacks and failed-event recovery before launch.
Detect2 requirements
Detect: reviewed evidence and remaining work
RequirementImplementationLocal verificationHosted reference/demo verificationRemaining workReviewed
DE-01Administrative audit recordsOverall requirementPartialRestricted audit access and fixed retention maintenance implemented.Passed: database checks for audit permissions, retention and award-linked evidence. Full event coverage not assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Review event coverage and verify live scheduling and retention expectations.
DE-02Monitoring and alert responseOverall requirementPartialDatabase and maintenance monitoring configured; alert response incomplete.Not yet assessed through an alert-delivery and response exercise.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Verify alert delivery, ownership and response procedures in operation.
Respond1 requirement
Respond: reviewed evidence and remaining work
RequirementImplementationLocal verificationHosted reference/demo verificationRemaining workReviewed
RS-01Incident responseOverall requirementNo reviewed evidenceNo completed security incident procedure and exercise evidenced.Not yet assessed.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Complete the incident procedure and a recorded practice exercise.
Recover2 requirements
Recover: reviewed evidence and remaining work
RequirementImplementationLocal verificationHosted reference/demo verificationRemaining workReviewed
RC-01Backup coverage and recovery targetsOverall requirementPartialLocal restore procedure and infrastructure protection settings prepared; recovery targets incomplete.Backup coverage and recovery targets not yet assessed. See the separate data-restoration exercise below.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Agree data-loss and recovery-time targets and verify backup coverage.
RC-02Data restorationOverall requirementPartialRepeatable local database restoration procedure implemented.Passed: isolated restore with synthetic records and integrity checks. Realistic volumes and application recovery not tested.Hosted reference/demo not assessed. Future representative-demo checks use synthetic data; client launch checks remain separate.Verify realistic data volumes, application recovery and live restoration.

Dated work

Progress history

The timeline records completed work. It is not a security score. A numerical trend needs repeated reviews of the same requirements; the first snapshot starts that record.

  1. Initial security baseline recorded

    Selected requirements were organized under the six NIST CSF functions, with evidence limits and remaining work.

  2. Local database restoration exercised

    A synthetic backup was restored and checked for data and relational integrity.

  3. Account and database access checks extended

    Local checks covered required MFA configuration, session revocation, account blocking and restricted application database access.

  4. Audit-maintenance permissions narrowed

    Local tests verified fixed maintenance permissions and retention of award-linked evidence.

  5. Service-password recovery exercised

    Password-authenticated local tests verified rotation, login blocking, connection termination and recovery.

Review snapshots1 recorded
Compare counts only when the requirement scope is unchanged.
ReviewedScopeRequirementsNo reviewed evidencePartialImplementedLocally testedLive verified
selected-baseline-v123416120

Before each installation goes live

Client launch checks

Confirm enabled settings, integrations and installation conformity with synthetic accounts. Changes from the assessed product release or configuration require review and testing of the affected controls. These checks do not require a full reassessment using customer data.

Read the account access and audit protections update for the recent product changes.

Discuss your installation