assessment-results: uuid: f90f8cd3-8b97-4f6e-a79c-86076723ac49 metadata: title: IFA SYSTEM1234 Assessment Results last-modified: "2026-05-12T02:46:09.00000-00:00" version: 1.0.0 oscal-version: 1.2.2 revisions: - title: IFA GoodRead Continuous Monitoring Assessment Results June 2023 last-modified: "2024-02-01T13:57:28.355446-04:00" version: 202306-002 oscal-version: 1.1.2 links: - href: '#ec0dad37-54e0-40fd-a925-6d0bdea94c0d' rel: version-history remarks: This OSCAL version of the IFA Assessment Results was importing an nonexisting Assessment Plan. - title: IFA SYSTEM1234 Continuous Monitoring Assessment Results last-modified: "2025-07-06T15:05:10.355446-04:00" version: 202306-002 oscal-version: 1.1.3 links: - href: '#8da1dfe1-4aec-48e2-bacb-431ad61486c2' rel: version-history remarks: This OSCAL version of the IFA Assessment Results is part of OSCAL content v1.1.3 release. roles: - id: assessor title: IFA Security Controls Assessor parties: - uuid: e7730080-71ce-4b20-bec4-84f33136fd58 type: person name: Amy Assessor member-of-organizations: - 3a675986-b4ff-4030-b178-e953c2e55d64 - uuid: 3a675986-b4ff-4030-b178-e953c2e55d64 type: organization name: Important Federal Agency short-name: IFA links: - href: https://www.ifa.gov rel: website responsible-parties: - role-id: assessor party-uuids: - e7730080-71ce-4b20-bec4-84f33136fd58 remarks: In this version of the artifact, the content was updated to OSCAL v1.1.3 and the system name was changed. Imported Assessment Plan was corrected. Other enhancements were implemented. import-ap: href: ../../ap/xml/ifa_assessment-plan.xml local-definitions: activities: - uuid: cf5d53fe-6043-4c68-9ed6-6b258909febf title: Test System Elements for Least Privilege Design and Implementation description: The activity and it steps will be performed by the assessor via their security automation platform to test least privilege design and implementation of the system's elements, specifically the cloud account infrastructure, as part of continuous monitoring. props: - name: method value: TEST steps: - uuid: 57f8cfb8-fc3f-41d3-b938-6ab421c92574 title: Configure Cross-Account IAM Role Trust for SYSTEM1234 and Assessor AwesomeCloud Accounts description: The IFA SYSTEM1234 system engineer will coordinate with the assessor's engineering support staff to configure an IAM role trust. A service account for automation with its own role with the assessor's AwesomeCloud account can assume the role for read-only assessor operations within the SYSTEM1234 Product Team's AwesomeCloud account for continuous monitoring of least privilege. remarks: |- This step is complete. SYSTEM1234 Product Team and SCA Engineering Support configured the latter's cross-account role trust and authentication and authorization in to the former's account on May 29, 2023. - uuid: 976aadad-b1ce-475b-aa6c-e082537e7902 title: Automate Cross-Account Login to SYSTEM1234 AwesomeCloud Account description: The assessor's security automation platform will create a session from their dedicated will obtain access to the SYSTEM1234 Product Team's AwesomeCloud account with their single sign-on credentials to a read-only assessor role. remarks: |- This step is complete. SYSTEM1234 Product Team and SCA Engineering Support tested scripts from the security automation platform interactively on May 30, 2023, to confirm they work ahead of June 2023 continuous monitoring cycle. - uuid: 18ce4e19-7432-4484-8e75-2dd8f05668cf title: Analyze SYSTEM1234 Developer and System Engineer Roles for Least Privilege description: | Once authenticated and authorized with a cross-account session, the security automation pipeline will execute scripts developed and maintained by the assessor's engineering support staff. It will analyze the permitted actions for the developer and system engineer roles in the SYSTEM1234 Product Team's AwesomeCloud account to confirm they are designed and implement to facilitate only least privilege operation. Examples are included below. * For the SYSTEM1234 developer role in their AwesomeCloud account, the developer role may only permit the user with this role to check the IP addresses and status of the Awesome Compute Service server instances. This role will not permit the user to create, change, or delete the instances. Similarly, the developer will permit a user to perform actions to see IP addresses of an Awesome Load Balancer instance, but not add, change, or delete the instances. * For the SYSTEM1234 system engineer role in their AwesomeCloud account, the system engineer role may only permit actions where the user can add, change, or delete instances for approved services (i.e. Awesome Compute Service, Awesome Load Balancer, et cetera). The role may not permit actions by the user for any other service. related-controls: control-selections: - include-controls: - control-id: ac-6.1 responsible-roles: - role-id: assessor party-uuids: - e7730080-71ce-4b20-bec4-84f33136fd58 results: - uuid: a1d20136-37e0-42aa-9834-4e9d8c36d798 title: IFA SYSTEM1234 Continuous Monitoring Results June 2023 description: Automated monthly continuous monitoring of the SYSTEM1234 information system's cloud infrastructure recorded observations below. Additionally, contingent upon the confidence level of the observations and possible risks, confirmed findings may be opened. start: "2023-06-02T08:31:20-04:00" end: "2023-06-02T08:46:51-04:00" local-definitions: tasks: - uuid: 35876484-aa4b-494d-95a2-0d1cc04eb47e type: action title: Test System Elements for Least Privilege Design and Implementation description: The activity and it steps will be performed by the assessor via their security automation platform to test least privilege design and implementation of the system's elements, specifically the cloud account infrastructure, as part of continuous monitoring. associated-activities: - activity-uuid: cf5d53fe-6043-4c68-9ed6-6b258909febf subjects: - type: component include-all: {} reviewed-controls: control-selections: - include-controls: - control-id: ac-6.1 observations: - uuid: 8807eb6e-0c05-43bc-8438-799739615e34 title: AwesomeCloud IAM Roles Test - SYSTEM1234 System Engineer Role description: Test AwesomeCloud IAM Roles for least privilege design and implementation. methods: - TEST types: - finding subjects: - subject-uuid: 551b9706-d6a4-4d25-8207-f2ccec548b89 type: component collected: "2023-06-02T08:31:20-04:00" expires: "2023-07-01T00:00:00-04:00" remarks: |- The assessor's security automation platform analyzed all roles specific to the SYSTEM1234 Product Team, not those managed by the Office of Information Technology. The `IFA-SYSTEM1234-SystemEngineer` role in their respective AwesomeCloud account permitted use of the following high-risk actions. * awesomecloud:auditlog:DeleteAccountAuditLog * awesomecloud:secmon:AdministerConfigurations Both of these actions are overly permissive and not appropriate for the business function of the staff member assigned this role. - uuid: 4a2fb32e-9be9-43cf-b717-e9e47de061bd title: AwesomeCloud IAM Roles Test - SYSTEM1234 Developer Role description: Test AwesomeCloud IAM Roles for least privilege design and implementation. methods: - TEST types: - finding subjects: - subject-uuid: 551b9706-d6a4-4d25-8207-f2ccec548b89 type: component collected: "2023-06-02T08:31:20-04:00" expires: "2023-07-01T00:00:00-04:00" remarks: The assessor's security automation platform detected that the developer's role is permitted to perform only permissible actions in the SYSTEM1234 AwesomeCloud account in accordance with the agency's least privilege policy and procedures. risks: - uuid: 0cfa750e-3553-47ba-a7ba-cf84a884d261 title: SYSTEM1234 System Engineers Have Over-Privileged Access to Cloud Infrastructure Account description: A user in the SYSTEM1234 cloud environment with the privileges of a system engineer can exceed the intended privileges for their related business function. They can delete all historical audit records and remove important security monitoring functions for the IFA Security Operations Center staff. statement: |- An account without proper least privilege design and implementation can be used to surreptitiously add, change, or delete cloud infrastructure to the too managing all links to IFA's communication to public citizens, potentially causing significant harm with no forensic evidence to recover the system. Regardless of the extent and duration of a potential incident, such a configuration greatly increases the risk of an insider threat if there were likely to a potential insider threat in the SYSTEM1234 Product Team. If such an insider threat existed and acted with this misconfigruation, the resulting event could cause significant financial and reputational risk to IFA's Administrator, executive staff, and the agency overall. status: investigating findings: - uuid: 45d8a6c2-1368-4bad-9ba0-7141f0a32889 title: SYSTEM1234 AwesomeCloud Account's System Engineer Role Permits High Risk Actions description: |- The assessor's security automation platform detected that the system engineer's role is permitted to perform the following actions in the SYSTEM1234 AwesomeCloud account. * Delete and reset account audit logs. * Add, change, or delete security monitoring configurations in the Awesome Security Monitor service used by the IFA Security Operations Center. The system engineer is not permitted to modify these services and their role was incorrectly configured. target: type: objective-id target-id: ac-6.1_obj description: This is a finding. status: state: not-satisfied implementation-statement-uuid: d5f9b263-965d-440b-99e7-77f5df670a11 related-observations: - observation-uuid: 8807eb6e-0c05-43bc-8438-799739615e34 related-risks: - risk-uuid: 0cfa750e-3553-47ba-a7ba-cf84a884d261 back-matter: resources: - uuid: ec0dad37-54e0-40fd-a925-6d0bdea94c0d title: IFA GoodRead Continuous Monitoring Assessment Results June 2023 rlinks: - href: https://github.com/usnistgov/oscal-content/archive/refs/tags/v1.3.0.zip media-type: application/oscal+zip - uuid: 8da1dfe1-4aec-48e2-bacb-431ad61486c2 title: IFA SYSTEM1234 Continuous Monitoring Assessment Results rlinks: - href: https://github.com/usnistgov/oscal-content/archive/refs/tags/v1.4.0.zip media-type: application/oscal+zip