assessment-plan: uuid: 74c1f5ed-7b04-49e4-a89b-f8b0120715fd metadata: title: IFA SYSTEM1234 Assessment Plan published: "2026-05-13T12:30:00.00000-00:00" last-modified: "2026-05-12T02:36:09.00000-00:00" version: 1.1.0 oscal-version: 1.2.2 revisions: - title: IFA GoodRead Assessment Plan last-modified: "2024-02-01T13:57:28.355446-04:00" version: "1.0" oscal-version: 1.1.2 links: - href: '#60077e84-e62f-4375-8c6c-b0e0d4560c5f' rel: version-history remarks: This OSCAL version of the IFA Assessment Plan is part of the v 1.3.0 OSCAL content release. - title: IFA SYSTEM1234 Assessment Plan last-modified: "2025-07-06T15:05:10.355446-04:00" version: 1.1.0 oscal-version: 1.1.3 links: - href: '#97f36be8-fec0-4fa6-bcdf-e3f838eba040' rel: version-history remarks: This OSCAL version of the IFA Assessment Plan is part of the v 1.4.0 OSCAL content release. roles: - id: assessor title: IFA Security Control Assessor parties: - uuid: e7730080-71ce-4b20-bec4-84f33136fd58 type: person name: Amy Assessor member-of-organizations: - 3a675986-b4ff-4030-b178-e953c2e55d64 - uuid: 3a675986-b4ff-4030-b178-e953c2e55d64 type: organization name: Important Federal Agency short-name: IFA links: - href: https://www.ifa.gov rel: website responsible-parties: - role-id: assessor party-uuids: - e7730080-71ce-4b20-bec4-84f33136fd58 remarks: In this version of the artifact, the content was updated to OSCAL v1.2.2. import-ssp: href: ../../ssp/xml/ifa_ssp.xml local-definitions: activities: - uuid: 52277182-1ba3-4cb6-8d96-b1b97aaf9d6b title: Examine System Elements for Least Privilege Design and Implementation description: 'The activity and it steps will be performed by the assessor and facilitated by owner, ISSO, and product team for the IFA SYSTEM1234 system with necessary information and access about least privilege design and implementation of the system''s elements: the application, web framework, server, and cloud account infrastructure.' props: - name: method value: EXAMINE steps: - uuid: 733e3cbf-e398-46b6-9c02-a2cb534c341e title: Obtain Network Access via VPN to IFA SYSTEM1234 Environment description: The assessor will obtain network access with appropriately configured VPN account to see admin frontend to the application for PAO staff, which is only accessible via VPN with an appropriately configured role for PAO staff accounts. - uuid: 4ce7e0b4-d69e-4b80-a700-8600b4d4d933 title: Obtain Credentials and Access to AWSomeCloud Account for IFA SYSTEM1234 System description: The assessor will obtain access to the SYSTEM1234 Product Team's AWSomeCloud account with their single sign-on credentials to a read-only assessor role. - uuid: 3d0297de-e47b-4360-b9c3-cf5c425f86cd title: Obtain Application Access Provided by Product Team description: The assessor will obtain non-privileged account credentials with the PAO staff role to test this role in the application does not permit excessive administrative operations. - uuid: 64ca1ef6-3ad4-4747-97c6-40890222463f title: Confirm Load Balancer Blocks Access to Admin Frontend from Internet description: The assessor will confirm that the load balancer for public access does not allow access to Admin Frontend of the application from the Internet. - uuid: 715f0592-166f-44f6-bb66-d99623e035dc title: Confirm SYSTEM1234's PAO Role Cannot Manage Users description: The assessor will confirm that user's logged into the SYSTEM1234 Application with the PAO staff role cannot add, modify, or disable users from the system. - uuid: 4641957b-a0fa-4c61-af1a-d3e9101efe40 title: Confirm Django Admin Panel Not Available description: The assessor will confirm with web-based interface and API methods users with the PAO Staff role cannot access the Django admin panel functions and interactively change application's database records. related-controls: control-selections: - include-controls: - control-id: ac-6.1 responsible-roles: - role-id: assessor party-uuids: - e7730080-71ce-4b20-bec4-84f33136fd58 reviewed-controls: control-selections: - include-controls: - control-id: ac-6.1 control-objective-selections: - include-all: {} assessment-subjects: - type: component description: The assessor for the IFA SYSTEM1234 Project, including the application and infrastructure for this information system, are within scope of this assessment. include-all: {} tasks: - uuid: b3504d22-0e75-4dd7-9247-618661beba4e type: action title: Examine Least Privilege Design and Implementation associated-activities: - activity-uuid: 0d243b23-a889-478f-9716-6d4870e56209 subjects: - type: component include-all: {} responsible-roles: - role-id: assessor remarks: | Per IFA's use of NIST SP-800 53A, the assessor, with the support of the owner, information system security officer, and product team for the IFA SYSTEM1234 project, will examine least privilege design and implementation with the following: * list of security functions (deployed in hardware, software, and firmware) and security-relevant information for which access must be explicitly authorized; * system configuration settings and associated documentation; back-matter: resources: - uuid: 60077e84-e62f-4375-8c6c-b0e0d4560c5f title: IFA GoodRead Assessment Plan rlinks: - href: https://github.com/usnistgov/oscal-content/archive/refs/tags/v1.3.0.zip media-type: application/oscal+zip remarks: This OSCAL version of the IFA Assessment Plan released with the OSCAL content v1.3.0. - uuid: 97f36be8-fec0-4fa6-bcdf-e3f838eba040 title: IFA SYSTEM1234 Assessment Plan rlinks: - href: https://github.com/usnistgov/oscal-content/archive/refs/tags/v1.4.0.zip media-type: application/oscal+zip remarks: This OSCAL version of the IFA Assessment Plan was released with the OSCAL content v1.4.0.