What needs attention
4 controls need a decision before this workspace is ready to share.
Access to production and sensitive data is reviewed and re-certified every quarter by system owners.
Third-party vendors are assessed for security and data-handling risk before onboarding and annually thereafter.
Source code and prompts are scanned for hardcoded secrets and PII on every commit.
Every pull request runs static analysis and blocks on critical findings.
Framework coverage
One control can support several requirements.
Recent evidence activity
A traceable record of what changed and who reviewed it.
re-checked AC-2 and confirmed MFA enforcement
co-signed AI-1 after reviewing the prompt boundary
opened a fix for SC-4, secret exposed in a prompt
added evidence for DP-3
| Control | Frameworks | Status | Source | Expert | Last checked |
|---|---|---|---|---|---|
| AC-2MFA enforced on all accounts | Passing | Org | JO | 2 min ago | |
| AC-7Quarterly access reviews | Failing | Org | None | 1 hr ago | |
| VR-1Vendor risk assessments | In review | Org | None | yesterday | |
| GV-1Information security policy | Passing | Org | JO | 3 hr ago | |
| DP-3Data encrypted at rest and in transit | Passing | Org | JO | 2 min ago | |
| BC-2Backups tested and recoverable | Passing | Org | JO | yesterday | |
| AI-1No indirect prompt-injection paths | Passing | AI | JO | 4 min ago | |
| AI-2Agent tool access allowlisted | Passing | AI | JO | 14 min ago | |
| SC-4No secrets in source or prompts | Failing | Code | None | 1 hr ago | |
| SC-1Dependencies free of known CVEs | Passing | Code | None | 8 min ago | |
| SC-2Static analysis on every PR | In review | Code | None | 30 min ago | |
| LM-1Audit logging on critical systems | Passing | Org | JO | 1 hr ago |