{ "$comment": "Public machine-readable KSI status for Tarly Cowork (FedRAMP 20x). Auto-generated nightly; do not edit by hand.", "provider": "Pincus Technologies Inc", "service": "Tarly Cowork", "fedRampPackageId": "FR2628650874", "catalog": { "title": "FedRAMP Consolidated Rules for 2026 \u2014 Key Security Indicators", "version": "2026.09.13.02", "source": "https://github.com/FedRAMP/rules" }, "generated-at": "2026-09-15T22:55:05.266857+00:00", "summary": { "drifted": 1, "false": 0, "inherited": 0, "partial": 2, "total": 46, "true": 44, "unknown": 0 }, "ksis": [ { "id": "KSI-CED-RAT", "name": "Reviewing All Training", "category": "Cybersecurity Education", "statement": "The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 15, "passing": 15 }, "evidence-manifest-sha256": "7e72f6dd817cf8757bbae32fbea9f2d53b3a4d24b3da2a979d4f55daed3f2ea2" }, { "id": "KSI-CMT-LMC", "name": "Logging Changes", "category": "Change Management", "statement": "Modifications to the cloud service offering are logged and monitored.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 9, "passing": 9 }, "evidence-manifest-sha256": "091cebc8ae91a14c6a7e9c7608a34cf30ecdfab8b235a431062c3ced95f505ae" }, { "id": "KSI-CMT-RMV", "name": "Redeploying vs Modifying", "category": "Change Management", "statement": "Changes to machine-based information resources are executed through the redeployment of version controlled resources rather than direct modification wherever reasonable.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 4, "passing": 4 }, "evidence-manifest-sha256": "a932f3f5175223dab48bc69d2517026fdcffb32ab9b1a2423dfb5b5d45d3977f" }, { "id": "KSI-CMT-RVP", "name": "Reviewing Change Procedures", "category": "Change Management", "statement": "The effectiveness of documented change management procedures is persistently reviewed.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 4, "passing": 4 }, "evidence-manifest-sha256": "55dd8eadbf96bd9577daa27d80dffd03307235b2376063e5fc8c8a8c18481f59" }, { "id": "KSI-CMT-VTD", "name": "Validating Throughout Deployment", "category": "Change Management", "statement": "Persistent testing and validation of changes throughout deployment is automated.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 3, "passing": 3 }, "evidence-manifest-sha256": "aae87fea69b73711c1d8835be746fe0cf80d899d43443a56c1c1d2e917d49774" }, { "id": "KSI-CNA-DFP", "name": "Defining Functionality and Privileges", "category": "Cloud Native Architecture", "statement": "The functionality and privileges for infrastructure and services are strictly defined.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "284555050a96073f9d4430dc2a85a7b952dcaf6ec5f53079eafabfdb4ee6825b" }, { "id": "KSI-CNA-EIS", "name": "Enforcing Intended State", "category": "Cloud Native Architecture", "statement": "Automated services are used to persistently assess the security of all machine-based information resources and automatically enforce their intended operational state.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 7, "passing": 7 }, "evidence-manifest-sha256": "f6fb7b1d1791cc1619cf49810e2cf7e17c8eca2ecb27dc69c915a0b023943a59" }, { "id": "KSI-CNA-IBP", "name": "Implementing Best Practices", "category": "Cloud Native Architecture", "statement": "The use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 7, "passing": 7 }, "evidence-manifest-sha256": "9909c43995df2f3e6a1f5cb91db10bd20e345a50c1b96f63faba5eb2635b9ea8" }, { "id": "KSI-CNA-MAT", "name": "Minimizing Attack Surface", "category": "Cloud Native Architecture", "statement": "Machine-based information resources are persistently reviewed to ensure they have a minimal attack surface and that lateral movement is minimized if compromised.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 11, "passing": 11 }, "evidence-manifest-sha256": "0dd877d8e44d1778f9c11b5b94bbdd73af2ae88e29b2e6099d129aa9b4c85a06" }, { "id": "KSI-CNA-OFA", "name": "Optimizing for Availability", "category": "Cloud Native Architecture", "statement": "Machine-based information resources are persistently reviewed to ensure they are appropriately optimized for high availability and rapid recovery.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 12, "passing": 12 }, "evidence-manifest-sha256": "0d6f1313d16040a4d2ce9c83333e1098c4feb83f3071a495d5bd041baf6ffc4f" }, { "id": "KSI-CNA-RNT", "name": "Restricting Network Traffic", "category": "Cloud Native Architecture", "statement": "Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 5, "passing": 5 }, "evidence-manifest-sha256": "b390860720e475f1191d147ebcfed1fb02fb658ca5dee8598f001b95c1540b8c" }, { "id": "KSI-CNA-RVP", "name": "Reviewing Protections", "category": "Cloud Native Architecture", "statement": "The effectiveness of protection against denial of service attacks and other unwanted activity for machine-based information resources is persistently reviewed.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 7, "passing": 7 }, "evidence-manifest-sha256": "4f9a70a530e5bd6d0c1ba3c19ac0fabf5a6907157d65ae5406f168fcde75920d" }, { "id": "KSI-CNA-ULN", "name": "Using Logical Networking", "category": "Cloud Native Architecture", "statement": "Logical networking and related capabilities are used and persistently reviewed to enforce traffic flow controls.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 2, "passing": 2 }, "evidence-manifest-sha256": "b069d0947cf4b6179e8af7b2531fa4271ff429a21988f4644055921050f49be4" }, { "id": "KSI-IAM-AAM", "name": "Automating Account Management", "category": "Identity and Access Management", "statement": "The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.", "status": "partial", "status-label": "Partially met", "drift": true, "checks": { "total": 7, "passing": 6 }, "evidence-manifest-sha256": "5f4eb9a5ef06eb867cb49a3ee7e6e529093a574eed5db348cdc188c0cfdb15cf", "remediation": { "risk": "medium", "scheduled-completion": null } }, { "id": "KSI-IAM-APM", "name": "Adopting Passwordless Methods", "category": "Identity and Access Management", "statement": "Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 4, "passing": 4 }, "evidence-manifest-sha256": "bdc79d4721a622844bab58fac1fcec631c3ed3d2eb4603ad781fea9e94c8957d" }, { "id": "KSI-IAM-ELP", "name": "Ensuring Least Privilege", "category": "Identity and Access Management", "statement": "Identity and access management measures are used and persistently reviewed to ensure each user or device can only access the resources they need.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 5, "passing": 5 }, "evidence-manifest-sha256": "1826b7e55de37751e960c750e392a78133d5cfcf7f334b2461ce3ec34a37a627" }, { "id": "KSI-IAM-JIT", "name": "Authorizing Just-in-Time", "category": "Identity and Access Management", "statement": "A least-privileged, role and attribute-based, and just-in-time security authorization model is used and persistently reviewed for all user and non-user accounts and services.", "status": "partial", "status-label": "Partially met", "drift": false, "checks": { "total": 6, "passing": 5 }, "evidence-manifest-sha256": "43c7e00a1f2506fcadd78de2e41260b603a1aee117500daac98d31027db4b8f9", "remediation": { "risk": "medium", "scheduled-completion": null } }, { "id": "KSI-IAM-SNU", "name": "Securing Non-User Authentication", "category": "Identity and Access Management", "statement": "Appropriately secure authentication methods are used and persistently reviewed for non-user accounts and services.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "3bfd5d36e90c0c22670af110d373897aa7be2aab9e01dfe64d04173b72d0d7eb" }, { "id": "KSI-IAM-SUS", "name": "Responding to Suspicious Activity", "category": "Identity and Access Management", "statement": "Accounts with privileged access are disabled or otherwise secured in response to suspicious activity.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 4, "passing": 4 }, "evidence-manifest-sha256": "f5f8283bb3d5d168a54cb6724f7785ebec33b5a807fe14b97a74118a3aee9949" }, { "id": "KSI-INR-AAR", "name": "Generating After Action Reports", "category": "Incident Response", "statement": "Incident after action reports are generated and lessons learned are persistently incorporated.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 13, "passing": 13 }, "evidence-manifest-sha256": "b68b62b501b04c8d3d1610d2fdd30dafa17fd550cdb5d98df0f65505451bcb76" }, { "id": "KSI-INR-RIR", "name": "Reviewing Incident Response Procedures", "category": "Incident Response", "statement": "The effectiveness of documented incident response procedures is persistently reviewed.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 9, "passing": 9 }, "evidence-manifest-sha256": "5f9750501b65d815cda0b758bf67ef5a3a42f37d0cff0781d1b6f99aa8cd1183" }, { "id": "KSI-INR-RPI", "name": "Reviewing Past Incidents", "category": "Incident Response", "statement": "Past incidents are persistently reviewed for patterns or vulnerabilities that were not previously apparent or identified.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 7, "passing": 7 }, "evidence-manifest-sha256": "ffe64fb87c8a045f35186155f93f4568f842a20c43ba702375e0962ce7820ea2" }, { "id": "KSI-MLA-ALA", "name": "Authorizing Log Access", "category": "Monitoring, Logging, and Auditing", "statement": "A least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 10, "passing": 10 }, "evidence-manifest-sha256": "4657992d085dcf4313fbad0b7e4ab6ab30200d5ca306e39ee7fb315fbd9a3370" }, { "id": "KSI-MLA-EVC", "name": "Evaluating Configurations", "category": "Monitoring, Logging, and Auditing", "statement": "The configuration of machine-based information resources, especially infrastructure as code, is persistently evaluated and tested.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "eceee6f105959759c9511434d271f68e4e68b6848eb80deb0b7a6412d8ecc202" }, { "id": "KSI-MLA-LET", "name": "Logging Event Types", "category": "Monitoring, Logging, and Auditing", "statement": "A list of information resources and event types that will be logged, monitored, and audited is maintained and persistently reviewed to ensure these activities occur.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 3, "passing": 3 }, "evidence-manifest-sha256": "9723b28fbacf5c839c425317732886865d1bf5c728538003cf8537cafa94b1bc" }, { "id": "KSI-MLA-OSM", "name": "Operating SIEM Capability", "category": "Monitoring, Logging, and Auditing", "statement": "A Security Information and Event Management (SIEM) or similar system(s) is used and persistently reviewed for centralized, tamper-resistant logging of events, activities, and changes.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 15, "passing": 15 }, "evidence-manifest-sha256": "83eb2333b5565a99769344cf1c4c58d9e6ea8fb57b9283aefe511393020228f1" }, { "id": "KSI-MLA-RVL", "name": "Reviewing Logs", "category": "Monitoring, Logging, and Auditing", "statement": "Logs are persistently reviewed and audited.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 8, "passing": 8 }, "evidence-manifest-sha256": "b27c0f79bfc4b88ffd4f7b0155b151a98320d7e799d3243151dbdaabf2dbef25" }, { "id": "KSI-PIY-GIV", "name": "Generating Inventories", "category": "Policy and Inventory", "statement": "Authoritative sources are used to automatically generate real-time inventories of all information resources when needed.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 8, "passing": 8 }, "evidence-manifest-sha256": "a608b5ec7e5d348d3dd1aa9267eca044e05aff352e3c6e7d9f2451a0a30888ae" }, { "id": "KSI-PIY-RES", "name": "Reviewing Executive Support", "category": "Policy and Inventory", "statement": "Executive support for achieving the provider's security goals is persistently reviewed and demonstrated.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "f61d0b57b74103aa5e66b14cd397b062390a529cedf66aa72bdbcca32a269482" }, { "id": "KSI-PIY-RIS", "name": "Reviewing Investments in Security", "category": "Policy and Inventory", "statement": "The effectiveness of the provider's investments in achieving security goals is persistently reviewed.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 9, "passing": 9 }, "evidence-manifest-sha256": "14d8cdb16242e98e8fb65ce495f0a864705e5b14f26a72de3d94d07c33c80e4e" }, { "id": "KSI-PIY-RSD", "name": "Reviewing Security in the SDLC", "category": "Policy and Inventory", "statement": "The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 11, "passing": 11 }, "evidence-manifest-sha256": "9c40238d444f1a703f85c3ff4abf7dfc822813d2af093d3d97c6b84834391a46" }, { "id": "KSI-PIY-RVD", "name": "Reviewing Vulnerability Disclosures", "category": "Policy and Inventory", "statement": "The effectiveness of the provider's vulnerability disclosure program is persistently reviewed.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 5, "passing": 5 }, "evidence-manifest-sha256": "56f5483c96a928d5aa6da0c0a5ecc9a5edf04f60b3e242f73b0f34f0dad0e027" }, { "id": "KSI-RPL-ABO", "name": "Aligning Backups with Objectives", "category": "Recovery Planning", "statement": "The alignment of machine-based information resource backups with defined recovery objectives is persistently reviewed.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "30009e174806b6850ac0488000fc0742c13241276a3ee44961bfa881c2946c59" }, { "id": "KSI-RPL-ARP", "name": "Aligning Recovery Plan", "category": "Recovery Planning", "statement": "The alignment of recovery plans with defined recovery objectives is persistently reviewed.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "cf0f68818b485d2cd54e578b40a879a6b42144af40d955db6c9bc7bf3f19e325" }, { "id": "KSI-RPL-RRO", "name": "Reviewing Recovery Objectives", "category": "Recovery Planning", "statement": "The desired Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and persistently reviewed for alignment with the provider's business needs and capabilities.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "3203900b53a9dd83832ebeeb7e2e6b919f867e1cfedf19888e62e6dfe8e32474" }, { "id": "KSI-RPL-TRC", "name": "Testing Recovery Capabilities", "category": "Recovery Planning", "statement": "The capability to recover from incidents and contingencies aligned with defined recovery objectives is persistently tested.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "864a23f0adb50cfe028559125b125eb747ff38ed7367cb6f78110e3027252d70" }, { "id": "KSI-SCR-MIT", "name": "Mitigating Supply Chain Risk", "category": "Supply Chain Risk", "statement": "Persistently identify, review, and mitigate potential supply chain risks.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 5, "passing": 5 }, "evidence-manifest-sha256": "79a05a1f30c66ac77fb28308a222f8a6e28762a77b02ed42bb876625872113df" }, { "id": "KSI-SCR-MON", "name": "Monitoring Supply Chain Risk", "category": "Supply Chain Risk", "statement": "Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 3, "passing": 3 }, "evidence-manifest-sha256": "5f5468115f022bc3389d9293481a4abba63848293e6f2aad129bf530bd7150b9" }, { "id": "KSI-SVC-ACM", "name": "Automating Configuration Management", "category": "Service Configuration", "statement": "The configuration of machine-based information resources is managed using automation and persistently reviewed for drift.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 21, "passing": 21 }, "evidence-manifest-sha256": "ffec4f546a1af052cd1b9f829b3ed91092a68c0d142414926aac150da4b53721" }, { "id": "KSI-SVC-ASM", "name": "Automating Secret Management", "category": "Service Configuration", "statement": "Management, protection, and regular rotation of digital keys, certificates, and other secrets is automated and persistently reviewed.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "c3accfc2f12fb271a8f0208f7f86b81935380e5ba48615c8e020805fbba4132f" }, { "id": "KSI-SVC-EIS", "name": "Evaluating and Improving Security", "category": "Service Configuration", "statement": "Information resources are persistently evaluated for opportunities to improve security and those improvements are persistently made.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "12fffffe2841d8c1adba723b45a425415a08e657df6abf0dc0720c9dec0c870d" }, { "id": "KSI-SVC-PRR", "name": "Preventing Residual Risk", "category": "Service Configuration", "statement": "Plans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "cffacf1a9ff1cae0ca655d35b0a3b587052b6c1fb8d56dbebd18d9e97ac22995" }, { "id": "KSI-SVC-RUD", "name": "Removing Unwanted Data", "category": "Service Configuration", "statement": "Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 9, "passing": 9 }, "evidence-manifest-sha256": "dfc368dd65bb718fb63b2adb078835ff5b775c2dd25ea58e91a13e024dc4476d" }, { "id": "KSI-SVC-SIN", "name": "Securing Information", "category": "Service Configuration", "statement": "Information is encrypted or otherwise secured from unwanted access or modification.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 4, "passing": 4 }, "evidence-manifest-sha256": "47c59e4eb19a932858f77eca85b109292190c5e5bd50c4aea069188435f1ffad" }, { "id": "KSI-SVC-VCM", "name": "Validating Communications", "category": "Service Configuration", "statement": "The authenticity and integrity of communications between machine-based information resources is persistently validated using automation.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 8, "passing": 8 }, "evidence-manifest-sha256": "d60db3705cf2360d8a7c23820ebbc9611415a8727e0e5145c3959b6472057750" }, { "id": "KSI-SVC-VRI", "name": "Validating Resource Integrity", "category": "Service Configuration", "statement": "Use cryptographic methods to validate the integrity of machine-based information resources.", "status": "true", "status-label": "Met", "drift": false, "checks": { "total": 6, "passing": 6 }, "evidence-manifest-sha256": "839a285fcd4148312a0e48f5e75aed8721598a65a24e7e590a86d06bc7f57986" } ] }