Project

General

Profile

Actions

Support #452

open

OAM: CMMC / ITAR compliance program — gap analysis to TS/SCI facility-clearance path

Support #452: OAM: CMMC / ITAR compliance program — gap analysis to TS/SCI facility-clearance path

Added by Charles N 1 day ago. Updated 1 day ago.

Status:
New
Priority:
Normal
Assignee:
-
Target version:
-
Start date:
08/27/2026
Due date:
% Done:

0%

Estimated time:

Description

Umbrella for pillar 4 of the September Full Court Press (plan of record: https://community.turnsys.com/t/313).

Goal

Fully CMMC/ITAR compliant and on the path to TS/SCI facility clearance.

Scope (first pass — gap analysis before remediation)

  • Inventory existing controls: AGENTS.md already mandates SSH-only access, ticket-governed changes, audit logging (Discourse #298), credential centralization (#440 Bitwarden migration in flight)
  • Map environment against CMMC 2.0 Level 1/2 domains (AC, AU, AT, CM, IA, IR, MA, MP, PE, PS, PT, RA, RM, CA, SI)
  • ITAR: identify US-person access controls, export-controlled data locations, access boundary definitions
  • Gap report → SSP outline + POA&M (Discourse doc, tickets for remediation items)
  • Wazuh (#438) as compliance SIEM foundation — FIM, log retention, audit rules
  • Facility clearance path: prerequisites, timeline, external counsel/consultant requirements (founder decision)

Dependencies

  • Pillar 2 OAM (monitoring/syslog/hardening) provides the technical substrate
  • #438 Wazuh rebuild, #440 credential migration, #427 network device credentials

Constraints

  • Sole-founder R&D environment; private residence DC; shoestring budget — pragmatism over checkbox theater
  • Every control must be agent-verifiable where possible (this is also the zero-trust DB-proxy direction in AGENTS.md)

Updated by Charles N 1 day ago Actions #1

  • Tracker changed from Bug to Support
Actions

Also available in: PDF Atom