Sample Program

Interactive Mock Program Workspace

Select an artifact type to review sample outputs for SCTM, residual risk, POA&M, and control outcomes. All data below is non-production placeholder content.

Program Snapshot

Synthetic Data
Assessment IDDEMO-A-2026-0007
SystemDEMO - Mission Support Platform
FrameworkJSIG NIST 800-53 Rev 5
Completion92%

Selectable Example Artifacts

Mock traceability matrix with controls, implementation, and evidence linkage.

ControlRequirementImplementationEvidenceStatus
AC-2Manage system and privileged accounts with defined approval and review cycles.Central IAM workflow enforces approval, provisioning, and quarterly account recertification.IAM policy v4.2, account recertification exportMeets
IA-2Enforce multifactor authentication for privileged and remote access paths.Identity provider requires MFA for privileged roles and external access entry points.MFA enforcement screenshot, privileged role policyPartial
CM-6Establish and maintain baseline secure configuration settings.Hardened baselines are applied via infrastructure as code and configuration drift checks.Configuration baseline checklist, drift scan reportGap
AU-6Review and analyze audit logs for security-relevant events.Security operations reviews log aggregation dashboards daily with escalation playbooks.SIEM weekly review report, escalation ticket sampleMeets
IR-4Implement incident handling procedures and notification workflows.Incident response runbooks map detection, triage, containment, and reporting requirements.Incident response SOP, tabletop exercise summaryPartial

Sample RMF Phase Progress

1. Categorize

Capture mission context, registration profile, and CIA impact levels.

complete

2. Select

Filter baseline controls from framework metadata and overlays.

complete

3. Implement

Document control narratives and attach objective evidence.

complete

4. Assess

Run scoring and track assessor findings and remediation.

in progress

5. Authorize

Assemble package for AO decision and residual risk statement.

pending

6. Continuous Monitoring

Schedule evidence refresh and reassessment cadence.

pending