NIST CSF 2.0

Security progress

Guided by NIST Cybersecurity Framework (CSF) 2.0. This page shows the status of 23 selected requirements for Military OS, what has been checked and what remains.

Evidence snapshot Internal review · Shared product and operating practices

Current evidence covers shared product development and local testing. Customer deployment and operational verification have not yet been assessed.

What this evidence covers

Checks use synthetic test records, simulated external services, isolated local databases and selected configuration profiles. Some checks also cover the local demo organization; the evidence is not limited to that organization. It does not establish behavior with a customer's actual data or operating environment.

Shared-code results apply to the reviewed code, configuration and cases exercised. Each client deployment needs verification of its enabled features, settings, integrations, data imports, permissions, data volumes and recovery arrangements.

A client-specific fork is a separate version of the code. Its changes and affected security controls need review and testing; the original codebase's results do not automatically verify the fork. Record the release or fork revision and configuration assessed for each installation.

Current snapshot

Implementation and verification

23 selected requirements · 0 live verified

Implementation

What code, configuration or procedures exist for each requirement, including unfinished work.

Local verification

Which checks passed and their limits. A passing check covers the stated cases, not the entire security requirement.

Deployment & operations

Not yet assessed. Each customer environment and any code fork require verification within their own scope.

The evidence table separates these stages. The overall ratings below retain the original assessment: a requirement can remain partial while several local checks have passed.

Overall requirement ratings
No reviewed evidence
4No completed evidence was found in the review scope.
Partial
16Some work exists; part remains unfinished or unverified.
Implemented
1Code or configuration exists; the full behavior has not been verified.
Locally tested
2Local checks passed for the stated scope. This does not verify a live installation.
Live verified
0Evidence demonstrates operation in a specified live installation.
Requirement counts by NIST CSF function
Govern

3 total · 1 no reviewed evidence, 2 partial

Identify

2 total · 1 no reviewed evidence, 1 partial

Protect

13 total · 1 no reviewed evidence, 9 partial, 1 implemented, 2 locally tested

Detect

2 total · 2 partial

Respond

1 total · 1 no reviewed evidence

Recover

2 total · 2 partial

A partial requirement can contain several passing tests. Its status remains partial until the full stated requirement is supported. Local tests do not establish live operation.

Review the scope

Requirements and evidence

Open a function to review its requirements. On smaller screens, scroll tables horizontally to read all columns.

Requirement IDs are Military OS tracking labels, not NIST subcategory numbers. Dates identify the evidence review for each row; this page does not monitor installations automatically.

Govern3 requirements
Govern: reviewed evidence and remaining work
RequirementImplementationLocal verificationDeployment & operationsRemaining workReviewed
GV-01Supported information and service scopeOverall requirementPartialProduct information and operating scope documented.Not yet assessed through a completed client intake.Not yet assessed. Customer deployment and operating evidence required.Confirm each customer's information and contractual requirements before launch.
GV-02Security responsibilities and reviewsOverall requirementNo reviewed evidenceNo completed ownership and review record evidenced.Not yet assessed.Not yet assessed. Customer deployment and operating evidence required.Document accountable owners, review dates and risk decisions.
GV-03Suppliers and shared responsibilitiesOverall requirementPartialConnected services and their roles documented; responsibility review incomplete.Not yet assessed.Not yet assessed. Customer deployment and operating evidence required.Complete the supplier, support-access and data-responsibility review.
Identify2 requirements
Identify: reviewed evidence and remaining work
RequirementImplementationLocal verificationDeployment & operationsRemaining workReviewed
ID-01System and data inventoryOverall requirementPartialArchitecture and data definitions documented; installation inventory incomplete.Not yet assessed as a complete inventory.Not yet assessed. Customer deployment and operating evidence required.Complete the inventory for each installation and its operating accounts.
ID-02Threat and vulnerability reviewOverall requirementNo reviewed evidenceNo completed threat and vulnerability assessment evidenced.Not yet assessed.Not yet assessed. Customer deployment and operating evidence required.Record the assessment, remediation priorities and review process.
Protect13 requirements
Protect: reviewed evidence and remaining work
RequirementImplementationLocal verificationDeployment & operationsRemaining workReviewed
PR-01Identity checks at sign-inOverall requirementLocally testedSign-in boundary and deployed-mode authentication guards implemented.Passed: selected identity-boundary tests with simulated identity-provider calls.Not yet assessed. Customer deployment and operating evidence required.Verify real enrollment, callbacks and sign-out before launch.
PR-02Multi-factor authenticationOverall requirementPartialRequired authenticator-app MFA configured for all password accounts.Passed: configuration assertions across representative profiles. Real enrollment and recovery not tested.Not yet assessed. Customer deployment and operating evidence required.Verify live enrollment and recovery, plus separate operator-account MFA.
PR-03Role and record permissionsOverall requirementPartialServer role and record permissions implemented in reviewed routes.Passed: selected denied-access cases. Full privileged-route coverage not assessed.Not yet assessed. Customer deployment and operating evidence required.Complete coverage across privileged workflows and record scopes.
PR-04Account blocking and access removalOverall requirementPartialSession expiry, revocation, account blocking and permission refresh implemented.Passed: unit and isolated database checks of session and account access. Offboarding reviews remain outstanding.Not yet assessed. Customer deployment and operating evidence required.Verify complete account removal and periodic access reviews in operation.
PR-05Encrypted database connection settingsOverall requirementLocally testedCertificate verification required by deployed database connection settings.Passed: configuration rejection tests and force-encryption template checks. Actual TLS connections not tested.Not yet assessed. Customer deployment and operating evidence required.Test actual encrypted connections and certificate rejection before launch.
PR-06Stored data protectionOverall requirementImplementedDatabase encryption and separate public/private storage policies configured.Passed: database-encryption template assertion. Complete storage-policy behavior not assessed.Not yet assessed. Customer deployment and operating evidence required.Complete policy checks and verify the created storage and key access.
PR-07Service credentials and recoveryOverall requirementPartialService-database credential recovery procedure implemented; other secret procedures incomplete.Passed: password-authenticated database exercises for rotation, login blocking, disconnection and recovery.Not yet assessed. Customer deployment and operating evidence required.Complete other secret-rotation procedures and verify consumer updates in a live installation.
PR-08Separate application and operator accessOverall requirementPartialRestricted application database role and separate fixed-maintenance account implemented.Passed: isolated database permission checks; local demo role and maintenance checks. AWS isolation not tested.Not yet assessed. Customer deployment and operating evidence required.Verify installation isolation, deployed credentials and infrastructure permissions.
PR-09Browser requests and input handlingOverall requirementPartialRequest-origin checks, input limits, headers and image handling implemented in reviewed areas.Passed: selected request and upload checks. Complete route and abuse coverage not assessed.Not yet assessed. Customer deployment and operating evidence required.Extend coverage across routes and verify the live request boundary.
PR-10Code checks and release processOverall requirementPartialAutomated code checks configured; operating release procedures incomplete.Passed: lint, type and automated behavior checks on reviewed changes. Repository protections not assessed.Not yet assessed. Customer deployment and operating evidence required.Verify repository protections and document patch, release and rollback procedures.
PR-11Operator devices and accountsOverall requirementNo reviewed evidenceDevice and operator-account settings outside the repository assessment.Not yet assessed.Not yet assessed. Customer deployment and operating evidence required.Verify device protections, account access and staff procedures privately.
PR-12Personal data handlingOverall requirementPartialPublic-field, export and data-lifecycle rules implemented in reviewed areas.Passed: selected data-handling tests. Complete operational retention and erasure not assessed.Not yet assessed. Customer deployment and operating evidence required.Complete operational retention, erasure and support-data procedures.
PR-13Verified payment processingOverall requirementPartialProvider-result validation and paid issuance rules implemented.Passed: selected payment and issuance checks with simulated provider interactions. Actual callbacks not tested.Not yet assessed. Customer deployment and operating evidence required.Verify actual provider callbacks and failed-event recovery before launch.
Detect2 requirements
Detect: reviewed evidence and remaining work
RequirementImplementationLocal verificationDeployment & operationsRemaining workReviewed
DE-01Administrative audit recordsOverall requirementPartialRestricted audit access and fixed retention maintenance implemented.Passed: database checks for audit permissions, retention and award-linked evidence. Full event coverage not assessed.Not yet assessed. Customer deployment and operating evidence required.Review event coverage and verify live scheduling and retention expectations.
DE-02Monitoring and alert responseOverall requirementPartialDatabase and maintenance monitoring configured; alert response incomplete.Not yet assessed through an alert-delivery and response exercise.Not yet assessed. Customer deployment and operating evidence required.Verify alert delivery, ownership and response procedures in operation.
Respond1 requirement
Respond: reviewed evidence and remaining work
RequirementImplementationLocal verificationDeployment & operationsRemaining workReviewed
RS-01Incident responseOverall requirementNo reviewed evidenceNo completed security incident procedure and exercise evidenced.Not yet assessed.Not yet assessed. Customer deployment and operating evidence required.Complete the incident procedure and a recorded practice exercise.
Recover2 requirements
Recover: reviewed evidence and remaining work
RequirementImplementationLocal verificationDeployment & operationsRemaining workReviewed
RC-01Backup coverage and recovery targetsOverall requirementPartialLocal restore procedure and infrastructure protection settings prepared; recovery targets incomplete.Backup coverage and recovery targets not yet assessed. See the separate data-restoration exercise below.Not yet assessed. Customer deployment and operating evidence required.Agree data-loss and recovery-time targets and verify backup coverage.
RC-02Data restorationOverall requirementPartialRepeatable local database restoration procedure implemented.Passed: isolated restore with synthetic records and integrity checks. Realistic volumes and application recovery not tested.Not yet assessed. Customer deployment and operating evidence required.Verify realistic data volumes, application recovery and live restoration.

Dated work

Progress history

The timeline records completed work. It is not a security score. A numerical trend needs repeated reviews of the same requirements; the first snapshot starts that record.

  1. Initial security baseline recorded

    Selected requirements were organized under the six NIST CSF functions, with evidence limits and remaining work.

  2. Local database restoration exercised

    A synthetic backup was restored and checked for data and relational integrity.

  3. Account and database access checks extended

    Local checks covered required MFA configuration, session revocation, account blocking and restricted application database access.

  4. Audit-maintenance permissions narrowed

    Local tests verified fixed maintenance permissions and retention of award-linked evidence.

  5. Service-password recovery exercised

    Password-authenticated local tests verified rotation, login blocking, connection termination and recovery.

Review snapshots1 recorded
Compare counts only when the requirement scope is unchanged.
ReviewedScopeRequirementsNo reviewed evidencePartialImplementedLocally testedLive verified
selected-baseline-v123416120

Before each installation goes live

Verification in the customer environment

Launch checks must verify actual sign-in and recovery, account access, encrypted connections, storage, monitoring, backup restoration and scheduled maintenance. Local code checks do not replace those checks.

Read the account access and audit protections update for the recent product changes.

Discuss your installation