Implementation
What code, configuration or procedures exist for each requirement, including unfinished work.
NIST CSF 2.0
Guided by NIST Cybersecurity Framework (CSF) 2.0. This page shows the status of 23 selected requirements for Military OS, what has been checked and what remains.
Evidence snapshot Internal review · Shared product and operating practices
Current evidence covers shared product development and local testing. Customer deployment and operational verification have not yet been assessed.
Checks use synthetic test records, simulated external services, isolated local databases and selected configuration profiles. Some checks also cover the local demo organization; the evidence is not limited to that organization. It does not establish behavior with a customer's actual data or operating environment.
Shared-code results apply to the reviewed code, configuration and cases exercised. Each client deployment needs verification of its enabled features, settings, integrations, data imports, permissions, data volumes and recovery arrangements.
A client-specific fork is a separate version of the code. Its changes and affected security controls need review and testing; the original codebase's results do not automatically verify the fork. Record the release or fork revision and configuration assessed for each installation.
Current snapshot
23 selected requirements · 0 live verified
What code, configuration or procedures exist for each requirement, including unfinished work.
Which checks passed and their limits. A passing check covers the stated cases, not the entire security requirement.
Not yet assessed. Each customer environment and any code fork require verification within their own scope.
The evidence table separates these stages. The overall ratings below retain the original assessment: a requirement can remain partial while several local checks have passed.
3 total · 1 no reviewed evidence, 2 partial
2 total · 1 no reviewed evidence, 1 partial
13 total · 1 no reviewed evidence, 9 partial, 1 implemented, 2 locally tested
2 total · 2 partial
1 total · 1 no reviewed evidence
2 total · 2 partial
A partial requirement can contain several passing tests. Its status remains partial until the full stated requirement is supported. Local tests do not establish live operation.
Review the scope
Open a function to review its requirements. On smaller screens, scroll tables horizontally to read all columns.
Requirement IDs are Military OS tracking labels, not NIST subcategory numbers. Dates identify the evidence review for each row; this page does not monitor installations automatically.
| Requirement | Implementation | Local verification | Deployment & operations | Remaining work | Reviewed |
|---|---|---|---|---|---|
| GV-01Supported information and service scopeOverall requirementPartial | Product information and operating scope documented. | Not yet assessed through a completed client intake. | Not yet assessed. Customer deployment and operating evidence required. | Confirm each customer's information and contractual requirements before launch. | |
| GV-02Security responsibilities and reviewsOverall requirementNo reviewed evidence | No completed ownership and review record evidenced. | Not yet assessed. | Not yet assessed. Customer deployment and operating evidence required. | Document accountable owners, review dates and risk decisions. | |
| GV-03Suppliers and shared responsibilitiesOverall requirementPartial | Connected services and their roles documented; responsibility review incomplete. | Not yet assessed. | Not yet assessed. Customer deployment and operating evidence required. | Complete the supplier, support-access and data-responsibility review. |
| Requirement | Implementation | Local verification | Deployment & operations | Remaining work | Reviewed |
|---|---|---|---|---|---|
| ID-01System and data inventoryOverall requirementPartial | Architecture and data definitions documented; installation inventory incomplete. | Not yet assessed as a complete inventory. | Not yet assessed. Customer deployment and operating evidence required. | Complete the inventory for each installation and its operating accounts. | |
| ID-02Threat and vulnerability reviewOverall requirementNo reviewed evidence | No completed threat and vulnerability assessment evidenced. | Not yet assessed. | Not yet assessed. Customer deployment and operating evidence required. | Record the assessment, remediation priorities and review process. |
| Requirement | Implementation | Local verification | Deployment & operations | Remaining work | Reviewed |
|---|---|---|---|---|---|
| PR-01Identity checks at sign-inOverall requirementLocally tested | Sign-in boundary and deployed-mode authentication guards implemented. | Passed: selected identity-boundary tests with simulated identity-provider calls. | Not yet assessed. Customer deployment and operating evidence required. | Verify real enrollment, callbacks and sign-out before launch. | |
| PR-02Multi-factor authenticationOverall requirementPartial | Required authenticator-app MFA configured for all password accounts. | Passed: configuration assertions across representative profiles. Real enrollment and recovery not tested. | Not yet assessed. Customer deployment and operating evidence required. | Verify live enrollment and recovery, plus separate operator-account MFA. | |
| PR-03Role and record permissionsOverall requirementPartial | Server role and record permissions implemented in reviewed routes. | Passed: selected denied-access cases. Full privileged-route coverage not assessed. | Not yet assessed. Customer deployment and operating evidence required. | Complete coverage across privileged workflows and record scopes. | |
| PR-04Account blocking and access removalOverall requirementPartial | Session expiry, revocation, account blocking and permission refresh implemented. | Passed: unit and isolated database checks of session and account access. Offboarding reviews remain outstanding. | Not yet assessed. Customer deployment and operating evidence required. | Verify complete account removal and periodic access reviews in operation. | |
| PR-05Encrypted database connection settingsOverall requirementLocally tested | Certificate verification required by deployed database connection settings. | Passed: configuration rejection tests and force-encryption template checks. Actual TLS connections not tested. | Not yet assessed. Customer deployment and operating evidence required. | Test actual encrypted connections and certificate rejection before launch. | |
| PR-06Stored data protectionOverall requirementImplemented | Database encryption and separate public/private storage policies configured. | Passed: database-encryption template assertion. Complete storage-policy behavior not assessed. | Not yet assessed. Customer deployment and operating evidence required. | Complete policy checks and verify the created storage and key access. | |
| PR-07Service credentials and recoveryOverall requirementPartial | Service-database credential recovery procedure implemented; other secret procedures incomplete. | Passed: password-authenticated database exercises for rotation, login blocking, disconnection and recovery. | Not yet assessed. Customer deployment and operating evidence required. | Complete other secret-rotation procedures and verify consumer updates in a live installation. | |
| PR-08Separate application and operator accessOverall requirementPartial | Restricted application database role and separate fixed-maintenance account implemented. | Passed: isolated database permission checks; local demo role and maintenance checks. AWS isolation not tested. | Not yet assessed. Customer deployment and operating evidence required. | Verify installation isolation, deployed credentials and infrastructure permissions. | |
| PR-09Browser requests and input handlingOverall requirementPartial | Request-origin checks, input limits, headers and image handling implemented in reviewed areas. | Passed: selected request and upload checks. Complete route and abuse coverage not assessed. | Not yet assessed. Customer deployment and operating evidence required. | Extend coverage across routes and verify the live request boundary. | |
| PR-10Code checks and release processOverall requirementPartial | Automated code checks configured; operating release procedures incomplete. | Passed: lint, type and automated behavior checks on reviewed changes. Repository protections not assessed. | Not yet assessed. Customer deployment and operating evidence required. | Verify repository protections and document patch, release and rollback procedures. | |
| PR-11Operator devices and accountsOverall requirementNo reviewed evidence | Device and operator-account settings outside the repository assessment. | Not yet assessed. | Not yet assessed. Customer deployment and operating evidence required. | Verify device protections, account access and staff procedures privately. | |
| PR-12Personal data handlingOverall requirementPartial | Public-field, export and data-lifecycle rules implemented in reviewed areas. | Passed: selected data-handling tests. Complete operational retention and erasure not assessed. | Not yet assessed. Customer deployment and operating evidence required. | Complete operational retention, erasure and support-data procedures. | |
| PR-13Verified payment processingOverall requirementPartial | Provider-result validation and paid issuance rules implemented. | Passed: selected payment and issuance checks with simulated provider interactions. Actual callbacks not tested. | Not yet assessed. Customer deployment and operating evidence required. | Verify actual provider callbacks and failed-event recovery before launch. |
| Requirement | Implementation | Local verification | Deployment & operations | Remaining work | Reviewed |
|---|---|---|---|---|---|
| DE-01Administrative audit recordsOverall requirementPartial | Restricted audit access and fixed retention maintenance implemented. | Passed: database checks for audit permissions, retention and award-linked evidence. Full event coverage not assessed. | Not yet assessed. Customer deployment and operating evidence required. | Review event coverage and verify live scheduling and retention expectations. | |
| DE-02Monitoring and alert responseOverall requirementPartial | Database and maintenance monitoring configured; alert response incomplete. | Not yet assessed through an alert-delivery and response exercise. | Not yet assessed. Customer deployment and operating evidence required. | Verify alert delivery, ownership and response procedures in operation. |
| Requirement | Implementation | Local verification | Deployment & operations | Remaining work | Reviewed |
|---|---|---|---|---|---|
| RS-01Incident responseOverall requirementNo reviewed evidence | No completed security incident procedure and exercise evidenced. | Not yet assessed. | Not yet assessed. Customer deployment and operating evidence required. | Complete the incident procedure and a recorded practice exercise. |
| Requirement | Implementation | Local verification | Deployment & operations | Remaining work | Reviewed |
|---|---|---|---|---|---|
| RC-01Backup coverage and recovery targetsOverall requirementPartial | Local restore procedure and infrastructure protection settings prepared; recovery targets incomplete. | Backup coverage and recovery targets not yet assessed. See the separate data-restoration exercise below. | Not yet assessed. Customer deployment and operating evidence required. | Agree data-loss and recovery-time targets and verify backup coverage. | |
| RC-02Data restorationOverall requirementPartial | Repeatable local database restoration procedure implemented. | Passed: isolated restore with synthetic records and integrity checks. Realistic volumes and application recovery not tested. | Not yet assessed. Customer deployment and operating evidence required. | Verify realistic data volumes, application recovery and live restoration. |
Dated work
The timeline records completed work. It is not a security score. A numerical trend needs repeated reviews of the same requirements; the first snapshot starts that record.
Selected requirements were organized under the six NIST CSF functions, with evidence limits and remaining work.
A synthetic backup was restored and checked for data and relational integrity.
Local checks covered required MFA configuration, session revocation, account blocking and restricted application database access.
Local tests verified fixed maintenance permissions and retention of award-linked evidence.
Password-authenticated local tests verified rotation, login blocking, connection termination and recovery.
| Reviewed | Scope | Requirements | No reviewed evidence | Partial | Implemented | Locally tested | Live verified |
|---|---|---|---|---|---|---|---|
| selected-baseline-v1 | 23 | 4 | 16 | 1 | 2 | 0 |
Before each installation goes live
Launch checks must verify actual sign-in and recovery, account access, encrypted connections, storage, monitoring, backup restoration and scheduled maintenance. Local code checks do not replace those checks.
Read the account access and audit protections update for the recent product changes.
Discuss your installation