---
documentation_complete: false
name: Hypersphere
schema_version: 3.0.0
satisfies:
##
## BEGINNING OF:
## ACCESS CONTROL
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: AC-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Development, documentation, and dissemination of an organization-level, mission/business
        process-level, or a system-level access control policy, is outside the scope of the
        HyperSphere.
    - key: b
      text: |
        Designation of an organization-defined official to manage the development,
        documentation, and dissemination of access control policy and procedures
        is outside the scope of the configuration of HyperSphere.

- control_key: AC-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        TO DO
        HyperSphere embeds the following types of accounts:
        (1) Human - admin portal?
        (2) Machine - API keys
    - key: b
      text: |
        AC-2(b) is an organizational control outside the scope of configuring HyperSphere.
    - key: c
      text: |
        AC-2(c) is an organizational control outside the scope of configuring HyperSphere.
    - key: d
      text: |
        AC-2(d) is an organizational control outside the scope of configuring HyperSphere.
    - key: e
      text: |
        AC-2(e) is an organizational control outside the scope of configuring HyperSphere.
    - key: f
      text: |
        AC-2(f) is an organizational control outside the scope of configuring HyperSphere.
    - key: g
      text: |
        AC-2(g) is an organizational control outside the scope of configuring HyperSphere.
    - key: h
      text: |
        AC-2(h) is an organizational control outside the scope of configuring HyperSphere.
    - key: i
      text: |
        AC-2(i) is an organizational control outside the scope of configuring HyperSphere.
    - key: j
      text: |
        AC-2(j) is an organizational control outside the scope of configuring HyperSphere.
    - key: k
      text: |
        AC-2(k) is an organizational control outside the scope of configuring HyperSphere.
    - key: l
      text: |
        AC-2(l) is an organizationla control outside the scope of configuring HyperSphere.

- control_key: AC-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |-
        Application-level access to the HyperSphere APIs is established through the
        HyperSphere Management Console.
        
        Currently this process cannot be automated. A HyperSphere Administrator must login
        to the HyperSphere Management Conole to add/remove/modify API keys.

# AC-2(2) NOTES:
#       The customer will be responsible for automatically removing or
#       disabling emergency and temporary accounts within the required
#       timeframe. A successful control response will need to address
#       all of the procedures and mechanisms involved in disabling these
#       accounts.
#
- control_key: AC-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |-
        Currently, HyperSphere does not have the capability to automatically remove or
        disable access. A HyperSphere Administrator must login to the HyperSphere
        Management Console and add/remove/modify API keys.

# AC-2(3) NOTES:
#       The customer will be responsible for automatically disabling user
#       accounts after the specified period of inactivity. A successful
#       control response will need to address all automated mechanisms
#       involved in disabling inactive accounts.
#
# ADMIN NOTE:
#       AC-2(2) disables temp/emergency accounts after period of time.
#       AC-2(3) differs by disabling *every other* account type
#
- control_key: AC-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        Disabling accounts to HyperSphere
        within an organization-defined time period
        when the accounts have expired currently requires manual intervention
        by a HyperSphere Administrator.
    - key: b
      text: |-
        Disabling accounts within an organization-defined time period when the accounts
        are no longer associated with a user or individual currently requires manual
        intervention by a HyperSphere Administrator.
    - key: c
      text: |
        Disabling accounts within an organization-defined time period when the accounts are in
        violation of organizational policy requires manual intervention by a HyperSphere
        Administrator.
    - key: d
      text: |-
        Disabling accounts within an organization-defined time period when the accounts
        have been inactive for an organization-defined time period currently requires manual
        intervention by a HyperSphere Administrator.

- control_key: AC-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |-
        HyperSphere currently does not have the capability to audit account creation, modification, enabling,
        disabling, and removal actions. This is currently a permanent finding and is planned to be remediated
        in a future release.

- control_key: AC-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |-
        HyperSphere currently does not have the capability to require that users log out after an organization-defined
        time period of expected inactivity or description of when to log out.

        This is currently a permanent finding.

- control_key: AC-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        HyperSphere has the capabilities to uniquely key quantum shadows.

- control_key: AC-2 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |-
        Establishing and administration of privileged user accounts in accordance with a role-based access scheme or
        an attribute-access scheme is supported. Available roles are defined in AC-2(2).
    - key: b
      text: |-
        Currently HyperSphere does not have the capability to monitor privileged role or attribute assignments. 
    - key: c
      text: |-
        Currently HyperSphere does not have the capability to monitor changes to roles or attributes.
    - key: d
      text: |-
        Revoking access when privileged role or attribute assignments are no longer appropriate is an organizational
        control outside the scope of HyperSphere configuration.

- control_key: AC-2 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        Currently, HyperSphere access is controlled by a HyperSphere Administrator. Controlling access through
        a dynamic API is planned for  a future release.

- control_key: AC-2 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: satisfied
  narrative:
    - text: |-
        HyperSphere provides mechanisms for unique accounts. Usage of shared or group accounts reflects an organizational
        control outside the scope of HyperSphere configuration. 

- control_key: AC-2 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        As of NIST 800-53 rev5, this control was withdrawn and incorporated
        into AC-2(k).

- control_key: AC-2 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        Enforcement of organization-defined circumstances and/or usage
        conditions for organization-defined system accounts is an organizational
        control outside the scope of HyperSphere configuration.

- control_key: AC-2 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        Monitoring system accounts for organization-defined atypical usage
        is the responsibility of the organization's security
        operations center, and outside the scope of HyperSphere configuration.
    - key: b
      text: |-
        Reporting atypical usage of system accounts to organization-defined
        personnel or roles is the responsibility of the organization's security
        operations center, and is outside the scope of HyperSphere configuration.

- control_key: AC-2 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |-
        Disabling accounts of individuals within an organization-defined time
        period of discovery of organization-defined significant risks is the
        responsibility of the organization, and outside the scope of HyperSphere
        configuration.

- control_key: AC-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        A control response detailing how HyperSphere
        enforces approved authorizations for logical access to
        information and system resources in accordance with
        applicable access control policies is forthcoming.

- control_key: AC-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        As of NIST 800-53 rev5, this control was withdrawn by NIST and incorporated into
        AC-6.

- control_key: AC-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        A control response is planned.

- control_key: AC-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        HyperSphere can assist an organization in enforcing organization-defined mandatory access control policy 
        over the set of covered subjects and objects specified in the policy, and where the policy is uniformly
        enforced across the covered subjects and objects within the system.
    - key: b
      text: |-
        HyperSphere can assist an organization in enforcing organization-defined mandatory access control policy
        over the set of covered subjects and objects specified in the policy, and where the policy specifies that a
        subject that has been granted access to information is constrained from doing any of the following:

           (1) Passing the information to unauthorized subjects or objects;
           (2) Granting its privilege to other subjects;
           (3) Changing one or more security attributes (specified by the policy)
           on subjects, objects, the system, or system components;
           (4) Chosing the security attributes and attribute values (specified by the policy)
           to be associated with newly created or modified objects; and
           (5) Changing the rules governing access control

    - key: c
      text: |-
        HyperSphere can assist an organization in the enforcement of organization-defined mandatory access control policy over the set
        of covered subjects and objects specified in the policy, and where the policy
        specifies that organization-defined subjects may explicity be granted
        organization-defined privilgees such that they are not limited by any
        defined subset (or all) of the above constraints, is the responsibility of the
        organization's identity management subsytem.

- control_key: AC-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        A control response is planned.
    - key: b
      text: |-
        A control response is planned.
    - key: c
      text: |-
        A control response is planned.
    - key: d
      text: |-
        A control response is planned.
    - key: e
      text: |-
        A control response is planned.

- control_key: AC-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned that outlines how HyperSphere prevents access to organization-defined
        security-relevant information except during secure, non-operable system states is planned.

- control_key: AC-3 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn by NIST
        and incorporated into MP-4 and SC-28.

- control_key: AC-3 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        A control response is planned.

- control_key: AC-3 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        A control response is planned.

- control_key: AC-3 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        Releasing information outside of HyperSphere only if
        the the recieving organization-defined system or system component provides
        organization-defined controls is a procedural requirement outside the
        scope of configuring HyperSphere.

        It is assumed that any user, system, or system component, with access
        to HyperSphere has an approved interconnection agreement.
    - key: b
      text: |-
        Releasing information outside of HyperSphere only if
        organization-defined controls are used to validate the appropriateness of
        the information designated for release is an organizaitonal control
        outside the scope of configuring HyperSphere.

- control_key: AC-3 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |-
        The HyperSphere does not have the ability to override its
        authentication controls nor is there a "master key" or "backdoored key" that would allow
        access to previously encrypted data. There are no hard coded passwords or API keys.

- control_key: AC-3 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        A control response is planned.

- control_key: AC-3 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - key: a
      text: |-
        HyperSphere installation is through automated mechanisms, such as Helm Charts for Kubernetes or RPM packages
        for Linux hosts. These mechanisms codify their assertions through source code, which is audited with every release
        of HyperSphere.
    - key: b
      text: |-
        Enforcement of an approved identity is an intrinsic property of 
        HyperSphere. HyperSphere cannot be configured to be out of compliance.
    - key: c
      text: |-
        The HyperSphere is installed and configured into Kubernetes
        environments through the use of Helm Charts, Kustomize, and custom resource
        definitions. Modification of these files, and further reloading of the
        HyperSphere to use the modified values, requires administrative
        access to the Kubernetes namespace that HyperSphere
        is deployed into. This is default, non-configurable behavior.

- control_key: AC-3 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere provides object level encryption to higher level data services. Enforcement of
        attribute-based access control policy over defined subjects and objects and control of access
        based upon organization-defined attributes to assume access permissions is a function
        of higher-level data services and outside the scope of HyperSphere configuration.

- control_key: AC-3 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere provides object level encryption to higher level data services. Providing
        organization-defined mechanisms to enable individuals to have access to organization-defined
        elements of their personally identifiable information is outside the scope of
        HyperSphere configuration.

- control_key: AC-3 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |-
        The HyperSphere assumes that all users and services
        accessing the API have full access to all data.

        The HyperSphere currently cannot be configured to
        enforce organizatin-defined mandatory access control policies over
        the set of covered subjects and objects specified in the policy.
    - key: b
      text: |-
        The HyperSphere assumes that all users and services
        accessing the API have full access to all data.

        The HyperSphere currently cannot be configured to
        enforce organizatin-defined discretionary access control policies over
        the set of covered subjects and objects specified in the policy.

- control_key: AC-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere provides object level encryption. Enforcing approved autorizations for controlling
        the flow of information within the system and between connected systems based on organization-defined
        information flow policies is outside the scope of HyperSphere configuration.

- control_key: AC-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere provides object level encryption. Using organization-defined security
        and privacy attributes associated with organization-defined information, source, and
        destination objects to enforce organization-defined information flow control policies as
        a basis for flow control decisions, is outside the scope of HyperSphere configuration.


- control_key: AC-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Future versions of HyperSphere will be protected by SELinux Type Enforcement
        when deployed on Red Hat Enterprise Linux-based hosts.

- control_key: AC-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere provides object level encryption. Enforcement of organization-defined
        flow control policies is outside the scope of HyperSphere configuration.

- control_key: AC-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        The HyperSphere is not an information flow enforcement
        capability.

- control_key: AC-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow control enforcement capability.

- control_key: AC-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow control enforcement capability.

- control_key: AC-4 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        HyperSphere is not a flow enforcement capability.
    - key: b
      text: |-
        HyperSphere is not a flow enforcement capability.

- control_key: AC-4 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow control capability.

- control_key: AC-4 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow control capability.

- control_key: AC-4 (16)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn by NIST
        and incorporated into AC-4.

- control_key: AC-4 (17)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        Downstream destination points authenticate to HyprSphere through
        secure API keys.

        The session established between HyperSphere
        and the downstream API consumer recieves a unique session ID.

        This is default, non-configurable behavior.

- control_key: AC-4 (18)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was incorporated into AC-16 by NIST.

- control_key: AC-4 (19)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (20)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (21)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (22)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (23)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (24)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is not an information flow enforcement capability.


- control_key: AC-4 (25)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (26)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (27)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (28)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (29)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        HyperSphere is not an information flow enforcement capability.
    - key: b
      text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (30)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (31)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-4 (32)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |-
        HyperSphere is not an information flow enforcement capability.
    - key: b
      text: |-
        HyperSphere is not an information flow enforcement capability.
    - key: c
      text: |-
        HyperSphere is not an information flow enforcement capability.
    - key: d
      text: |-
        HyperSphere is not an information flow enforcement capability.

- control_key: AC-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        It is recommended that a new organization-defined duty of
        "HyperSphere Administrator" be created.
    - key: b
      text: |
        The "HyperSphere Administrator" will need sufficient
        permissions to install, modify, and remove, HyperSphere

        Further elaboration of required access authorizations is forthcoming.

- control_key: AC-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        Authenticated users, or processes acting on behalf of users, only
        have access to HyperSphere data. Privileged user accesses,
        such as administrative access to the infrastructure hosting HyperSphere, is not provided.

- control_key: AC-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - key: a
      text: |
        HyperSphere provides object encryption. Access to encrypted objects is provided by sharing
        the decryption key with organization-defined individuals and roles who need access to the data.
    - key: b
      text: |
        HyperSphere provides object encryption. Access to encrypted objects is provided by sharing
        the decryption key with organization-defined individuals and roles who need access to the data.

- control_key: AC-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        An implementation of RBAC is planned for a future HyperSphere release.

- control_key: AC-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere provides encryption services through the use of an API. As such, network connection
        is a functional requirement.

- control_key: AC-6 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        Upon authentication to HyperSphere, users, or processes
        acting on their behalf, are isolated into a dedicated communication and
        data access session. Users are unable to access data, or communicate
        with other users, in separate sessions.

        This is default behavior and HyperSphere cannot
        be configured to be out of compliance with this control.

- control_key: AC-6 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Restricting privileged accounts on the system to organization-defined personnel
        or roles reflects a procedural control outside the scope of configuring
        HyperSphere.

- control_key: AC-6 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Prohibiting privileged access to the system by non-organizational users
        reflects a procedural control outside the scope of HyperSphere.

- control_key: AC-6 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        The HyperSphere only has one class of user, which can query
        HyperSphere and receive data.

        Periodic reviews to validate the need for such access is a procedural control
        outside the scope of configuring HyperSphere.
    - key: b
      text: |
        This is an organizational/procedural control outside the scope of
        configuring HyperSphere. It is up to the organization
        to review and validate users permissions and privileges.

- control_key: AC-6 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-6 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently os not log the execution of privileged functions.
        This capability is planned for a future release.

- control_key: AC-6 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        This capabiity is being reviewed for inclusion in a future HyperSphere release.
    - key: b
      text: |-
        This capability is being reviewed for inclusion in a future HyperSphere release.

- control_key: AC-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated
        into AC-7.

- control_key: AC-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Management of mobile devices is outside the scope
        of configuring HyperSphere.

- control_key: AC-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere currently does not support biometric logon attempts.

- control_key: AC-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        Usage of alternate organization-defined authentication factors is being evaluated for inclusion
        in a future HyperSphere release.
    - key: b
      text: |-
        Usage of alternate organization-defined authentication factors is being evaluated for inclusion
        in a future HyperSphere release.

- control_key: AC-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        The HyperSphere currently does not disaply an
        organization-defined system use notification message or banner to users
        before granting access to the system.

        This functionality is planned for a future version.
    - key: b
      text: |
        The HyperSphere currently does not display an
        organizatin-defined system use notification message or banner to users
        before granting access to the system.

        This functionality is planned for a future version.
    - key: c
      text: |
        The HyperSphere currently does not display an
        organizatin-defined system use notification message or banner to users
        before granting access to the system.

        This functionality is planned for a future version.

- control_key: AC-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere currently does not have the capability to
        notify the user, upon successful logon to the system, of the date and time
        of the last logon.

        This functionality is planned for a future version.

- control_key: AC-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere does not currently notify the user, upon
        successful logon, of the number of unsuccessful logon attempts since the
        last successful logon.

        This functionality is planned for a future version.

- control_key: AC-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere currently does not notify the user, upon
        successful logon, of the number of succesful logons, unsuccessful logon
        attempts, or both, during an organization-defined time period.

        This functionality is planned for a future version.

- control_key: AC-9 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere currently does not notify the user, upon successful
        logon, of changes to organization-defined security-related characteristics or
        parameters of the user's account during an organization-defined time period.

        This functionality is planned for a future version.

- control_key: AC-9 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere currently does not notify the user, upon successful
        logon, of additional organization-defined additional information.

        This functionality is planned for a future version.

- control_key: AC-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently, an authenticated user, or process acting on their behalf,
        can issue API calls to HyperSphere in any order
        their mission requires, to include simultanious sessions.

        As an API, this control negatively impacts the mission purpose
        of HyperSphere and is not implemented.

- control_key: AC-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Device management is outside the scope of the operation
        and configuration of HyperSphere.
    - key: b
      text: |
        Device management is outside the scope of the operation and configuration
        of HyperSphere.

- control_key: AC-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Device management is outside the scope of the operation and configuration
        of HyperSphere.

- control_key: AC-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        HyperSphere currently does not automatically terminate
        a user session after organization-defined conditions or trigger events
        requiring session disconnect.

        This capability will be incorporated into a future version of the
        HyperSphere.

- control_key: AC-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        The HyperSphere currently does not provide a logout capability
        for user-initiated communication sessions whenever authentication is used to
        gain access to organization-defined information resources.

        This capability will be incorporated into a future version of the
        HyperSphere.

- control_key: AC-12 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        HyperSphere currently does not display an explicit logout message
        to users indicating the termination of authenticated communications sessions.

        This functionality is planned for a future version of the
        HyperSphere.

- control_key: AC-12 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        HyperSphere currently does not display an explicity message to users
        inidcating that the session will end in an organization-defined time until
        end of session.

        This functionality is planned for a future version of the
        HyperSphere.

- control_key: AC-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        AC-2 and AU-6 by NIST.

- control_key: AC-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - key: a
      text: |-
        There are no user actions that can be performed on HyperSphere
        without identification or authentication. This is default, non-configurable
        behavior and HyperSphere cannot be configured to be
        out of compliance with this control.
    - key: b
      text: |-
        There are no user actions that can be performed on HyperSphere
        without identification or authentication. This is default, non-configurable
        behavior and HyperSphere cannot be configured to be
        out of compliance with this controls.

- control_key: AC-14 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        AC-14 by NIST.

- control_key: AC-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        As of NIST 80053 rev5, this control was withdrawn and incorporated into
        MP-3 by NIST.

- control_key: AC-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        A control response is planned.
    - key: b
      text: |-
        A control response is planned.
    - key: c
      text: |-
        A control response is planned.
    - key: d
      text: |-
        A control response is planned.
    - key: e
      text: |-
        A control response is planned.
    - key: f
      text: |-
        A control response is planned.

- control_key: AC-16 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere provides object encryption. Dynamic association of security and privacy
        attributes with organization-defined subjects and objects in accordance with the following security
        and privacy policies as information is created and combined is outside the scope of
        HyperSphere configuration.

- control_key: AC-16 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere provides object encryption. Providing authorized individuals (or processes acting on behalf
        of individuals) the capability to define or change the value of associated security and privacy
        attributes is outside the scope of HyperSphere configuration.

- control_key: AC-16 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-16 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-16 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-16 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-16 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-16 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-16 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-16 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AC-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        Documentation on the usage restrictions, configuration/connection requirements,
        and implementation guidance for remote access to HyperSphere
        is under development.
    - key: b
      text: |
        Documentation on how to authorize each type of remote access to HyperSphere prior to allowing
        such connections is under development.

- control_key: AC-17 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The ability to employ automated mechanisms to monitor and control remote access
        methods is under development.

- control_key: AC-17 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere utilizes FIPS 140 validated SSL, provided
        by the host compute platform, to implement crypographic mechanisms to protect
        the confidentiality and integrity of remote access sessions.

        There are no non-encrypted access mechanisms to HyperSphere.

        This is default, non-configurable, behavior and HyperSphere cannot
        be configured to be out of compliance with this control.

- control_key: AC-17 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Routing remote access throug authorized and managed network access control
        points is outside the scope of HyperSphere configuration.

- control_key: AC-17 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        Documentation on the authorization of privileged commands and access to security-relevant
        information via remote access only in a format that provides assessable evidence is planned.
    - key: b
      text: |
        HyperSphere operates as an API from which applications can encrypt their data. Remote access
        via an API is required for functionality of HyperSphere.

- control_key: AC-17 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into SI-4
        by NIST.

- control_key: AC-17 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        As a publicly available commercial technology, the HyperSphere API
        documentation is unclassified and available to all HyperSphere customers.

- control_key: AC-17 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        AC-3 (10) by NIST.

- control_key: AC-17 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        CM-7 by NIST.

- control_key: AC-17 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |
        The HyperSphere is a software application deployed upon a compute
        hosting environment, such as Kubernetes. It is the responsibility of the underlying
        platform to provide the capability to disconnect or disable remote access to the
        HyperSphere within an organization-defined time period.

- control_key: AC-17 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Detailed documentation on the HyperSphere API authentication process is
        currently under development.

- control_key: AC-18
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes regarding the establishment of wireless
        access usage restrictions are outside the scope of configuring HyperSphere.
    - key: b
      text: |
        Organizational processes regarding wireless access to the information
        system are outside the scope of configuring HyperSphere.

- control_key: AC-18 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Configuration of wireless networking is outside the scope of
        configuring HyperSphere.

- control_key: AC-18 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated
        into SI-4 by NIST.

- control_key: AC-18 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        Configuration of wireless networking is outside the scope of
        configuring HyperSphere.

- control_key: AC-18 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        Configuration of wireless networking is outside the scope of
        configuring HyperSphere.

- control_key: AC-18 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Radio antenna selection and calibration is outside the scope
        of configuring HyperSphere.

- control_key: AC-19
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Establishing organizational usage restrictions for mobile devices is outside
        the scope of configuring HyperSphere.
    - key: b
      text: |
        Authorization of mobile devices is outside the scope of configuring the
        HyperSphere.

- control_key: AC-19 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        MP-7 by NIST.

- control_key: AC-19 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        MP-7 by NIST.

- control_key: AC-19 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev5, this control was withdrawn and incorporated into
        MP-7 by NIST.

- control_key: AC-19 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational restrictions on the use of mobile devices is outside
        the scope of configuring HyperSphere.
    - key: b
      text: |
        Enforcement of organizational restrictions of mobile devices is
        outside the scope of configuring HyperSphere.
    - key: c
      text: |
        Restricting the connection of classified mobile devices to
        classified information systems is outside the scope of This control was withdrawn by NIST.
        HyperSphere configuration.

- control_key: AC-19 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Encryption strategies for mobile devices is outside
        the scope of configuring HyperSphere.

- control_key: AC-20
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes for establishing terms and conditions
        for accessing the information system from external information
        systems is outside the scope of configuring HyperSphere.

        Note HyperSphere provides a NIST 800-53 response catalog to assist
        organizations in documenting the organization-defined controls asserted
        to be implemented on a HyperSphere instance.
    - key: b
      text: |
        Organizational processes that prohibit the use of organization-controlled information using
        external systems is outside the scope of HyperSphere configuration.

- control_key: AC-20 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Verification of security control implementation on external systems,
        prior to allowing connectivity to HyperSphere, is outside the scope
        of HyperSphere configuration.
    - key: b
      text: |
        Retention of approved information system connection or processing
        agreements with organizational entities hosting the external
        information system is outside the scope of configuring HyperSphere.

- control_key: AC-20 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes regarding the restriction or
        prohibiting of the use of organization-controlled portable
        storage devices by authorized individuals on external information
        systems is outside the scope of configuring HyperSphere.

- control_key: AC-20 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes regarding the restriction or
        prohibiting of the use of non-organizationally owned
        information systems, system components, or devices to process,
        store, or transmit organizational information, is
        outside the scope of configuring HyperSphere.

- control_key: AC-20 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes regarding prohibiting the use of
        organization-defined network accessible storage devices in
        external information systems is beyond the scope of
        HyperSphere configuration.

- control_key: AC-20 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes that prohibit the use of organization-defined network
        accessible storage devices in external systems are outside the scope of
        the configuration and operation of HyperSphere.

- control_key: AC-21
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Facilitation of information sharing is outside the scope
        of configuring HyperSphere.
    - key: b
      text: |
        Employment of technology or processes to assist users in making
        information sharing/collaboration decisions is outside
        the scope of configuring HyperSphere.

- control_key: AC-21 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Enforcement of information-sharing decisions is outside
        the scope of configuring HyperSphere.

- control_key: AC-21 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Implementation of information search and retrieval services
        that enforce organization-defined information sharing restrictions
        is outside the scope of configuring HyperSphere.

- control_key: AC-22
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational processes regarding the designation of individuals
        authorized to post information onto a publicly accessible information
        system is outside the scope of configuring HyperSphere.
    - key: b
      text: |
        Training authorized individuals to ensure that publicly accessible
        information does not contain nonpublic information is outside the
        scope of configuring HyperSphere.
    - key: c
      text: |
        Reviewing the proposed content of information prior to posting onto
        the publicly accessible information system to ensure that nonpublic
        information is not included is outside the scope of HyperSphere
        configuration.
    - key: d
      text: |
        Reviewing content on the publicly accessible information system
        for nonpublic information at an organization-defined frequency and
        removal of such information, if discovered, is outside the scope of
        configuring HyperSphere.

- control_key: AC-23
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response regarding how HyperSphere can assist in the prevention of
        data mining is under development.

- control_key: AC-24
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response on how to establish proceures and implementation mechanisms to ensure
        organization-defined access control decisions are applied to each access request prior to
        access enforcement is planned.

- control_key: AC-24 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response regarding HyperSphere's enforcement of access control
        decisions is planned.

- control_key: AC-24 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Access control decisions to HyperSphere are based on API access keys,
        which are linked to specific applications and/or users.

- control_key: AC-25
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Implementation of a reference monitor is outside the scope of the
        configuration and operation of HyperSphere.
##
## BEGINNING OF:
## AWARENESS AND TRAINING CONTROLS
##

- control_key: AT-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.

- control_key: AT-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        As of NIST 800-53 rev4 this control was withdrawn
        and incorporated into PM-15.

- control_key: AT-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control reflects organizational procedure/policy and is not
        applicable to component-level configuration.
##
## BEGINNING OF:
## AUDIT AND ACCOUNTABILITY
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: AU-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        Development, documentation, and dissemination of a HyperSphere audit and accountability policy
        is under development.
    - key: b
      text: |
        Designation of an organizatin-defined official to manage the development, documentation, and dissemination
        of the audit and accountability policy and procedures is an organizational control outside the scope of
        HyperSphere configuration.
    - key: c
      text: |
        Review and update of the current audit and accountability policy and procedures is an organizational
        control outside the scope of HyperSphere configuration.

- control_key: AU-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        The HyperSphere audit subsystem is being designed to audit relevant
        events identified in Intelligence Community Standard Number 500-27
        (ICS 500-27).
    - key: b
      text: |
        The ability to export logs to a SIEM is under development.
    - key: c
      text: |
        The HyperSphere audit subsystem is currently under development.
    - key: d
      text: |
        The HyperSphere audit subsystem is being designed to audit relevant
        events identified in Intelligence Community Standard Numer 500-27
        (ICS 500-27). These events have been identified by the U.S. Department
        of Defense, U.S. Intelligence Community, NIST, and many other Federal agencies,
        as robust enough to support after-the-fact investigations of incidents.
    - key: e
      text: |
        HyperSphere reviews and pdates the event types selected for logging during every
        major release.

- control_key: AU-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AU-12.

- control_key: AU-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AU-12.

- control_key: AU-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AU-2.

- control_key: AU-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AU-6(9).

- control_key: AU-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        HyperSphere audit records contain
        the required information and cannot be configured to be out of
        compliance with this control.

- control_key: AU-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere audit subsystem is currently in development. A detailed
        control response on how to generate audit records containing additional information
        is planned.

- control_key: AU-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PL-9.

- control_key: AU-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        HyperSphere is a software application that is installed on top of an operating system
        or compute provider. The allocation of audit log storage capacity is a function of the
        operating system and/or compute provider, and outside the scope of HyperSphere
        configuration.

- control_key: AU-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The ability to export logs to a different system component, such as a SIEM,
        is under development.

- control_key: AU-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        The HyperSphere audit subsystem is being designed to uniquely identify
        multiple causes of audit processing failures. Configuring HyperSphere to alert,
        or take alternative actions such as shutdown, is detailed in AC-5(b).
    - key: b
      text: |-
        The HyperSphere audit subsystem is currently being developed. A further control
        response is planned.

- control_key: AU-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: inherited
  narrative:
    - text: |
        HyperSphere is an application that resides on a compute platform which provides storage, to
        explicitly include storage for audit logs. It is the responsibility of the compute platform
        to provide a warning to organization-defined personnel when allocated audit log storage
        volume reaches an organization-defined percentage of repository maximum audit log storage
        capacity.

- control_key: AU-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere audit subsystem is currently under development. A further control response is planned.

- control_key: AU-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Enforcement of configurable network communications traffic volume threshholds reflecting limits
        on audit log storage capacity and the rejection or delay of network traffic above these thresholds
        is the responsibility of the compute provider.

- control_key: AU-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere audit system is currently under development. A full control response
        is planned.

- control_key: AU-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere audit system is currently under development. A full control response
        is planned.

- control_key: AU-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational review and analysis of HyperSphere
        audit records for indications of organization-defined
        inappropriate or unusual activity is outside the scope
        of HyperSphere configuration.
    - key: b
      text: |
        Reporting findings of organization-defined inappropriate or
        unusual activity to organization-defined personnel or roles is
        outside the scope of HyperSphere configuration.
    - key: c
      text: |
        Adjustment of the level of audit record review, analysis, and reporting within the system when there
        is a change in risk based on law enforcement information, intelligence information, or other credible
        sources of information, is an organizational control outside the scope of HyperSphere configuration.

- control_key: AU-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Integration of audit record review, analysis, and reporting processes using organization-defined
        automated mechanisms is an organizational control outside the scope of HyperSphere configuration.

- control_key: AU-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SI-4.

- control_key: AU-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
	This is an organizational control outside the scope of HyperSphere configuration.

- control_key: AU-6 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: AU-6 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational capability to integrate analysis or audit
        records with analysis of additional organization-defined
        data/information collected from other sources to further
        enhance the ability to identify inappropriate or unusual
        activity is outside the scope of HyperSphere configuration.

        To aide in such organizational processes, note that many compute platforms, such as Kubernetes,
        offer "Log Forward" features that enable administrators to configure custom pipelines
        to send HyperSphere logs to remote destinations. These remote destinations, such as
        Elastic or Splunk, could integrate analysis of audit records with analysis
        of other types of data.

- control_key: AU-6 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational capability to correlate information from
        HyperSphere audit records with information obtained from monitoring
        physical access to further enhanced the ability to identify
        suspicious, inappropriate, unusual, or malevolent activity
        is outside the scope of HyperSphere configuration.

- control_key: AU-6 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational specification of permitted actions for
        information system processes, roles, and/or users, associated
        with the review, analysis, and reporting of audit
        information is outside the scope of HyperSphere configuration.

- control_key: AU-6 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes to perform full text analysis or audited
        privileged commands in a physically distinct component or subsystem
        of the information system, or other information system that is
        dedicated to that analysis, is outside the scope of HyperSphere
        configuration.

- control_key: AU-6 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Organizational processes to correlate information
        from nontechnical sources with audit information to enhance
        organization-wide situational awareness is outside
        the scope of HyperSphere configuration.

- control_key: AU-6 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AU-6.

- control_key: AU-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        The ability to perform on-demand audit record review, analysis, and reporting requirements
        and after-the-fact investigations of incidents is the general responsibility of SIEM tools,
        and outside the scope of HyperSphere configuration.
    - key: b
      text: |
        Preventing the alteration of original audit content or time ordering of audit events
        is the general responsibility of a SIEM tool, and outside the scope of HyperSphere
        configuration.

- control_key: AU-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The capability to process, sort, and search audit records for events of interest based on organization-defined
        fields is the general responsibility of a SIEM tool, and outside the scope of HyperSphere configuration.

- control_key: AU-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AU-7(1).

- control_key: AU-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - key: a
      text: |
        HyperSphere uses the internal system clock to generate time stamps and cannot be configured
        to be out of compliance with this control.
    - key: b
      text: |
        The audit subsystem is hard coded to only accept internationally recognized
        timezone settings. This ensures audit log timestamps can be mapped to
        Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).

        To ensure the underlying system clocks are accurate within an
        organization-defined granularity of time measurement, the system must be
        configured to synchronize with an authoritative time source. Such
        configuration is detailed in AU-8(1).

- control_key: AU-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-45(1).
        
- control_key: AU-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-45(2).


- control_key: AU-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        The protection of audit information and audit logging tools from unauthorized access, modification,
        and deletion, is the general responsibility of a SIEM or other audit collection system. This is
        out of scope of HyperSphere configuration.

    - key: b
      text: |
        Alerting organization-defined personnel or roles upon detection of unauthorized
        access, modification, or deletion of audit information, is the general responsibility
        of a SIEM. This is out of scope of HyperSphere configuration.

- control_key: AU-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Writing audit trails to hardware enforced, write-once media,
        is outside the scope of HyperSphere configuration.

- control_key: AU-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Storage of audit records onto a physically different system or
        system component than the component being audited is the
        responsibility of the centralized audit facility defined in
        AU-4 (1), "Transfer to Alternate Storage," and outside
        the scope of HyperSphere configuration.

- control_key: AU-9 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Enforcement of cryptographic protectionm is the responsibility of the centralized audit
        facility, and outside the scope of HyperSphere configuration.

- control_key: AU-9 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        Authorized access to the management of HyperSphere audit logging functionality is restricted
        to HyperSphere administrators. This is non-configurable default behavior, and HyperSphere cannot
        by configured to be out of compliance with this control.

- control_key: AU-9 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Per AU-4 (1), HyperSphere will be configured to offload audit records
        to a centralized audit facility. Enforcement of dual authorization
        for movement and/or deletion of organization-defined audit
        information is the responsibility of the centralized audit
        facility, and outside the scope of HyperSphere configuration.

- control_key: AU-9 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere audit subsystem is currently in development.
        A control response is planned.

- control_key: AU-9 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Per AU-4 (1), HyperSphere will be configured to offload audit records
        to a centralized audit facility. Ensuring the centralized facility runs
        a different operating system than the system or component being audited
        is outside the scope of HyperSphere configuration.

- control_key: AU-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        When running on a Common Criteria certified operating system, such as Red Hat Enterprise Linux,
        the HyperSphere audit subsystem integrates with the native audit system of the operating system.

        These Common Criteria certified audit subsystems provide irrefutable evidence that an individual
        (or process acting on behalf of an individual) has performed the actions to be covered by non-repudiation.

- control_key: AU-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned.
    - key: b
      text: |
        A control response is planned.

- control_key: AU-10 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned.
    - key: b
      text: |
        A control response is planned.

- control_key: AU-10 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: AU-10 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned.
    - key: b
      text: |
        A control response is planned.

- control_key: AU-10 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SI-7.

- control_key: AU-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |-
        The HyperSphere audit subsystem is currently under development.
        A control response is planned.

- control_key: AU-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Per AU-4 (1), HyperSphere will be configured to offload audit records
        to a centralized audit facility. Enuring the centralized audit facility
        employs organization-defined measures to ensure that long-term audit records
        generated by the system can be retrieved is outside the scope of HyperSphere
        configuration.

- control_key: AU-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        The HyperSphere audit subsystem is currently being developed.
        A control response is planned.
    - key: b
      text: |-
        The HyperSphere audit subsystem is currently being developed.
        A control response is planned.
    - key: c
      text: |-
        The HyperSphere audit subsystem is currently being developed.
        A control response is planned.

- control_key: AU-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Per AU-4 (1), HyperSphere will be configured to offload audit records
        to a centralized audit facility. Guidance on how to configure HyperSphere
        to offload audit records to the centralized audit facility is under development.

- control_key: AU-12 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Per AU-4 (1), HyperSphere will be configured to offload audit records
        to a centralized audit facility. Guidance on how to configure HyperSphere
        to offload audit records to the centralized audit facility is under development.

- control_key: AU-12 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere audit subsystem is currently being developed. A complete
        control response is planned.

- control_key: AU-12 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Per AU-4 (1), HyperSphere will be configured to offload audit records
        to a centralized audit facility. Ensuring the centralized audit facility has
        the capability for auditing the parameters of user query events for data sets containing
        personally identifiable informtion is outside the scope of HyperSphere configuration.
       
- control_key: AU-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Monitoring of organization-defined open source information
        and/or information sites at an organization-defined frequency for
        evidence of unauthorized disclosure of organizational information
        is outside the scope of HyperSphere configuration.

- control_key: AU-13 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of automated mechanisms to determine if
        organizational information has been disclosed in an
        unauthorized manner is outside the scope of
        HyperSphere configuration.

- control_key: AU-13 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Reviews of the open source information sites being monitored
        at an organization-defined frequency is outside the scope
        of HyperSphere configuration.

- control_key: AU-13 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of discovery techniques, processes, and tools to determine if external entities are replicating
        organizational information in an unauthorized manner is outside the scope of HyperSphere configuration.

- control_key: AU-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |-
        The HyperSphere audit subsystem is currently being developed.
        A control response is planned.
    - key: b
      text: |-
        The HyperSphere audit subsystem is currently being developed.
        A control response is planned.

- control_key: AU-14 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        The HyperSphere audit subsystem is an intrinsic property of HyperSphere, and initializes
        immediately upon launch of HyperSphere. This represents non-configurable behavior, and
        HyperSphere cannot be configured to be out of compliance with this control.

- control_key: AU-14 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AU-14.

- control_key: AU-14 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        The HyperSphere audit subsystem is currently in development.
        A further control response is planned.

- control_key: AU-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AU-5(5).

- control_key: AU-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of organization-defined methods for coordinating
        organization-defined audit information among external
        organizations when audit information is transmitted
        across organizational boundaries is outside the scope
        of HyperSphere configuration.

- control_key: AU-16 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is the responsibility of an organizations centralized audit facility, and
        outside the scope of HyperSphere configuration.

- control_key: AU-16 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Providing cross-organizational audit information to
        organization-defined organizations based on
        organization-defined cross-organizational sharing
        agreements is outside the scope of HyperSphere
        configuration.

- control_key: AU-16 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is the responsibility of an organization's centralized audit facility,
        and outside the scope of HyperSphere configuration.
##
## BEGINNING OF:
## SECURITY ASSESSMENT AND AUTHORIZATION
##

- control_key: CA-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: f
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: 
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        A control response detailing the interface characteristics, security, and controls,
        utilized within HyperSphere is planned. This will aide in the development of
        interconnection security agreements as defined in CA-3(a).
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SC-7(25).

- control_key: CA-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SC-7(26).

- control_key: CA-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SC-7(27).

- control_key: CA-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SC-7(28).

- control_key: CA-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SC-7(5).

- control_key: CA-3 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere requires authentication prior to accepting data. This is default
        and non-configurable behavior. HyperSphere cannot be configured to be out of
        compliance with this control.

- control_key: CA-3 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CA-2.

- control_key: CA-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: f
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: g
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CA-2.

- control_key: CA-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
       
- control_key: CA-7 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.
 
- control_key: CA-7 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.
 
- control_key: CA-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |-
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        HyperSphere is planning to document the interface characteristics, security
        and privacy requirements, and the nature of the information communicated by
        HyperSphere, in a future release.
    - key: c
      text: |
        HyperSphere currently does not have the capablity to terminate system connections
        ater organization-defined conditions. This is capability is planned for inclusion
        in a future release.
    - key: d
      text: |-
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CA-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.##
## BEGINNING OF:
## CONFIGURATION MANAGEMENT
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: CM-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        HyperSphere is in the process of publishing a NIST National Checklist to serve
        as the recommended configuration baseline of HyperSphere.
    - key: 
      text: |
        HyperSphere is in the process of publishing a NIST National Checklist to serve
        as the recommended configuration baseline of HyperSphere.

- control_key: CM-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        HyperSphere is in the process of publishing a NIST National Checklist to serve
        as the recommended configuration baseline of HyperSphere.

- control_key: CM-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        HyperSphere is in the process of publishing a NIST National Checklist to serve
        as the recommended configuration baseline of HyperSphere.

- control_key: CM-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-7(4).

- control_key: CM-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-7(4).

- control_key: CM-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-2 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: f
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: g
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: f
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        HyperSphere is in the process of publishing a NIST National Checklist to serve
        as the recommended configuration baseline of HyperSphere.

        This baseline will be published in the SCAP format, allowing for automated mechanisms
        to review and deploy the baseline.

- control_key: CM-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-3 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-3 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-3 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-3(7).

- control_key: CM-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control response was withdrawn by NIST and incorporated into CM-14.

- control_key: CM-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-5 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Future versions of HyperSphere plan to ship SELinux policies, which will assist
        with meeting this control.

- control_key: CM-5 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SI-7.

- control_key: CM-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        HyperSphere is in the process of publishing a NIST National Checklist
        for HyperSphere.
        
        Use of the NIST National Checklist
        for this system component is suggested as a supported,
        US Government recognized, vendor supported, baseline.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        HyperSphere is in the process of authoring SCAP-based configuration baselines,
        which will serve as the foundation for automated configuration assessment of HyperSphere.

- control_key: CM-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SI-7.

- control_key: CM-6 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-4.

- control_key: CM-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        HyperSphere is currently documenting the minimal required ports, protocols, and services,
        required for HyperSphere functionality.

- control_key: CM-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-7 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-7 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-7 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-7 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-7 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-8 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-8.

- control_key: CM-8 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-8 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-8 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-8 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        HyperSphere is in the process of publishing a NIST National Checklist, which will
        enumerate configuration items (specific to HyperSphere).
    - key: c
      text: |
        HyperSphere is in the process of publishing a NIST National Checklist, which will
        enumerate configuration items (specific to HyperSphere).
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        HyperSphere is developing a release engineering capability that will align
        to the requirements of DISA STIGs and NIST. Specifically, this will involve:

        - Ensure HyperSphere GPG Key Installed

        - Ensure gpgcheck Enabled for All YUM Package Repositories from HyperSphere
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-8(3).

- control_key: CM-11 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-11 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CM-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere is in the process of publishing SCAP-based automation content. This will
        support the usage of automated evaluations to ensure controls are in place.

- control_key: CM-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is in the process of developing a data action map for how HyperSphere
        collects, generates, transforms, uses, discloses, retains, and disposes of,
        system data.

- control_key: CM-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is in the process of generating cryptographically signed
        installation media. This will aide in the resolution of CM-14.
##
## BEGINNING OF:
## CONTINGENCY PLANNING
##

- control_key: CP-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: CP-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: f
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: g
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: h
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CP-2(3).

- control_key: CP-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-2 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-2 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CP-2.

- control_key: CP-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-7 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CP-7.

- control_key: CP-7 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-8 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned.
    - key: b
      text: |
        A control response is planned.
    - key: c
      text: |
        A control response is planned.
    - key: d
      text: |
        A control response is planned.

- control_key: CP-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-9 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
       This control is outside the scope of HyperSphere configuration.

- control_key: CP-9 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CP-9.

- control_key: CP-9 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-9 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-9 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CP-4.

- control_key: CP-10 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-10 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and addressed through tailoring.

- control_key: CP-10 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-10 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-10 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: CP-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.##
## BEGINNING OF:
## IDENTIFICATION AND AUTHENTICATION
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: IA-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
        
- control_key: IA-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response outlining how HyperSphere uniquely authenticates users,
        and uniquely associates that authentication with processes acting on their behalf,
        is under development.

- control_key: IA-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere does not currently support multi-factor authentication.

- control_key: IA-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere does not currently support multi-factor authentication.

- control_key: IA-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-2(1).

- control_key: IA-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-2(2).

- control_key: IA-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere does not provide the capability for shared accounts. This is default,
        non-configurable behavior, and HyperSphere cannot be configured to be out of compliance
        with this control.

- control_key: IA-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere does not support multi-factor authentication.
    - key: b
      text: |
        HyperSphere does not support multi-factor authentication.

- control_key: IA-2 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-2(6).

- control_key: IA-2 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere implements replay-resistant authentication via unique session identifiers.
        This is default, non-configurable, behavior. HyperSphere cannot be configured to be out
        of compliance with this control.

- control_key: IA-2 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-2(8).

- control_key: IA-2 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently requires username/password login. Currently, single sign-on
        is not supported.

- control_key: IA-2 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-2(6).

- control_key: IA-2 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisified
  narrative:
    - text: |
        HyperSphere currently does not support Personal Identity Verification-compliant
        credentials, such as Government PIV cards.

- control_key: IA-2 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisified
  narrative:
    - text: |
        HyperSphere currently does not sypport out-of-band authentication mechanisms.

- control_key: IA-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-3(1).

- control_key: IA-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-12(1).

- control_key: IA-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-12(2).

- control_key: IA-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-12(4).

- control_key: IA-4 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere does not support pairwise pseudonymous identifiers.

- control_key: IA-4 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere maintains user records in an embedded database. This is default,
        non-configurable, behavior. HyperSphere cannot be configured to be out of compliance
        with this control.

- control_key: IA-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: partial
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        HyperSphere has the capability to enforce password lengths of initial authenticators.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        HyperSphere currently does not have the mechanism to require changing of authenticators
        prior to their first use.
    - key: f
      text: |
        HyperSphere does not currently have the capability to force authenticator refresh after
        an organization-defined time period or when organization-defined events occur.
    - key: g
      text: |
        HyperSphere protects and encrypts user authenticator information. This is default,
        non-configurable, behavior. HyperSphere cannot be configured to be out of compliance
        with this control.
    - key: h
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: i
      text: |
        HyperSphere does not support group accounts. This is default, non-configurable,
        behavior. HyperSphere cannot be configured to be out of compliance with this control.

- control_key: IA-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere currently does not maintain a list of commonly-used, expected, or
        compromised passwords.
    - key: b
      text: |
        HyperSphere currently does not verify, when users create or update passwords, that the
        passwords are not found in the list of commonly-used passwords in IA-5(1)(a).
    - key: c
      text: |
        HyperSphere only transmits passwords over TLS protected channels. This is default,
        non-configurable, behavior. HyperSphere cannot be configured to be out of compliance
        with this control.
    - key: d
      text: |
        HyperSphere stores passwords using key derivation provided by argon2. This is default,
        non-configurable, behavior. HyperSphere cannot be configured to be out of compliance with
        this control.

        For details, refer to https://pages.nist.gov/800-63-4/sp800-63b.html.
    - key: e
      text: |
        HyperSphere does not currently require immediate selection of a new password upon
        account recovery. This is planned for a future release.
    - key: f
      text: |
        HyperSphere allows user selection of long passwords and phrases. This is default,
        non-configurable, behavior. HyperSphere cannot be configured out of compliance with
        this control.
    - key: g
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: h
      text: |
        HyperSphere does not currently enforce composition and complexity rules. This is
        planned for a future release.

- control_key: IA-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere does not currently support public-key authentication.
    - key: b
      text: |
        HyperSphere does not currently support public key infrastructure.

- control_key: IA-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-12(4).

- control_key: IA-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-5(1).

- control_key: IA-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-5 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-5 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere does not generate unencrypted static authenticators. This is default,
        non-configurable, behavior. HyperSphere cannot be configured to be out of compliance
        with this control.

- control_key: IA-5 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-5 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-5 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Dynamic authenticator binding is currently not supported by HyperSphere.

- control_key: IA-5 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-2(1) and IA-2(2).

- control_key: IA-5 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere does not support biometric-based authentication. This is default,
        non-configurable, behavior. HyperSphere cannot be configured to be out of compliance
        with this control.

- control_key: IA-5 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere does not support cached authenticators. This is default, non-configurable,
        behavior. HyperSphere cannot be configured to be out of compliance with this control.

- control_key: IA-5 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-5 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-5 (16)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-5 (17)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere does not support biometric-based authentication. This is default,
        non-configurable, behavior. HyperSphere cannot be configured to be out of
        compliance with this control.

- control_key: IA-5 (18)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
      
- control_key: IA-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere obscures authentication information during the authentication process.
        This is default, non-configurable, behavior. HyperSphere cannot be configured to be
        out of compliance with this control.

- control_key: IA-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        This control is satisfied when HyperSphere is deployed on Red Hat Enterprise Linux.

- control_key: IA-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        All HyperSphere users, regardless of organizational
        or non-organizational, receive unique system identifiers. This is default,
        non-configurable, behavior. HyperSphere cannot be configured to be
        out of compliance with this control.

- control_key: IA-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere does not currently support Personal Identity Verification-compliant
        credentials (PIV cards).

- control_key: IA-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
      
- control_key: IA-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-8(2).

- control_key: IA-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-8 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere does not currently accept federated or PKI credentials.

- control_key: IA-8 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-9.

- control_key: IA-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IA-9.

- control_key: IA-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere does not support Adaptive Authentication.

- control_key: IA-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere does not currently require reauthentication when organization-defined
        circumstances or situations occur. This capability is planned for a future release.

- control_key: IA-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-12 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-12 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-12 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-12 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IA-12 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.##
## BEGINNING OF:
## INCIDENT RESPONSE
##
- control_key: IR-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.3
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-4 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: IR-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.3
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.4
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.5
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.6
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.7
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.8
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.9
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.10
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.HVM).
    - key: f
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: g
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into IR-9.

- control_key: IR-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-9 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-9 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: IR-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to IR-4(11).##
## BEGINNING OF:
## MAINTENANCE
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: MA-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: f
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    
- control_key: MA-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into MA-2.

- control_key: MA-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-3 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.
    - key: b
      text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.
    - key: c
      text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.
    - key: d
      text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.
    - key: e
      text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.

- control_key: MA-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into MA-1 and MA-4.

- control_key: MA-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.
    - key: b
      text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.

- control_key: MA-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.
    - key: b
      text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.

- control_key: MA-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.

- control_key: MA-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This capability is being evaluated for inclusion in a future HyperSphere release.

- control_key: MA-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: MA-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: MA-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.
##
## BEGINNING OF:
## MEDIA PROTECTION
##

- control_key: MP-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of HyperSphere.
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of HyperSphere.
    - key: c
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of HyperSphere.

- control_key: MP-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        Restricting access to organization-defined types of digital and/or digital media to
        organization-defined personnel is an organizational control outside the scope of
        HyperSphere configuration.

- control_key: MP-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST and incorporated into MP-4(2).

- control_key: MP-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST and incorporated into MP-4(2).

- control_key: MP-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Physical control and secure storage of orgnaization-defined types of digital and/or non-digital
        media within organization-defined controlled areas is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        Protection of system media types defined in MP-4(a) until the media are destroyed or sanitized using
        approved equipment, techniques, and procedures, is an organizational control outside the scope
        of HyperSphere configuration.

- control_key: MP-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST and incorporated into SC-28(1).

- control_key: MP-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST and incorporated into MP-5.

- control_key: MP-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST and incorporated into MP-5.

- control_key: MP-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST and incorporated into SC-28(1).

- control_key: MP-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of HyperSphere.
    - key: b
      text: |
        This control reflects organizational procedures/policies, and is not
        applicable to the configuration of HyperSphere.

- control_key: MP-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-6 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST and incorporated into MP-6.

- control_key: MP-6 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST and incorporated into MP-6.

- control_key: MP-6 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST and incorporated into MP-6.

- control_key: MP-6 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-6 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control was withdrawn by NIST and incorporated into MP-7.

- control_key: MP-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: MP-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.##
## BEGINNING OF:
## PHYSICAL AND ENVIRONMENTAL PROTECTION
##

- control_key: PE-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Development, documentation, and dissemination of a physical
        and environmental protection policy reflects organizational
        procedure/policy and is outside the scope of HyperSphere
        configuration.
    - key: b
      text: |
        Designation of an organization-defined official to manage the development, documentation,
        and dissemination of the physical and environmental protection policy and procedures
        is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        Review and updates to the current phyiscal and environmental protection policies and procedures
        is outside the scope of HyperSphere configuration.

- control_key: PE-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Development, approval, and maintenance of a list
        of individuals with authorized access to the facility
        where the information system resides reflects organizational
        procedure/policy and is outside the scope of HyperSphere
        configuration.
    - key: b
      text: |
        Issuing authorization credentials for facility access
        reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        Reviewing the access list detailing authorized facility
        access by individuals at an organization-defined frequency
        reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: d
      text: |
        Removal of individuals from the facility access list when access
        is no longer required reflects organizational procedure/policy
        and is outside the scope of HyperSphere configuration.

- control_key: PE-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Authorizing physical access to the facility where the information
        system resides based on position or role reflects organizational
        procedures/policy and is outside the scope of HyperSphere
        configuration.

- control_key: PE-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Requiring two forms of identification from an organization-defined
        list of acceptable forms of identification for visitor access to
        the facility where the information system resides reflects
        organizational procedure/policy and is not applicable to
        HyperSphere configuration.

- control_key: PE-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Restricting unescorted access to the facility where the
        information system resides reflects organizational
        procedure/policy and is outside the scope of HyperSphere
        configuration.

- control_key: PE-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Enforcing physical access authorizations at organization-defined
        entry/exit points to the facility where the information system resides
        reflects organizational procedure/policy and is not applicable to
        HyperSphere configuration.
    - key: b
      text: |
        Maintaining physical access audit logs for organization-defined
        entry/exit points reflects organizational procedure/policy and
        is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        Providing organization-defined security safeguards to control access
        to areas within the facility officially designated as publicly
        accessible reflects organizational procedure/policy and
        is outside the scope of HyperSphere configuration.
    - key: d
      text: |
        Escorting visitors and monitoring visitor activity during
        organization-defined circumstances requiring visitor escorts
        and monitoring reflects organizational procedure/policy and
        is outside the scope of HyperSphere configuration.
    - key: e
      text: |
        Securing keys, combinations, and other physical access devices
        reflects organizational procedure/policy and
        is outside the scope of HyperSphere configuration.
    - key: f
      text: |
        Inventory of organization-defined physical access devices
        at an organization-defined frequency reflects organizational
        procedure/policy and is outside the scope of HyperSphere
        configuration.
    - key: g
      text: |
        Changing combinations and keys at an organization-defined frequency
        and/or when keys are lost, combinations are compromised, or individuals
        are transferred or terminated, reflects organizational procedure/policy
        and is outside the scope of HyperSphere configuration.

- control_key: PE-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Enforcing physical access authorizations to the information system
        in addition to the physical access controls for the facility at
        organization-defined physical spaces containing one or more components
        of the information system reflects organizational procedure/policy
        and is outside the scope of HyperSphere configuration.

- control_key: PE-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Performing security checks at an organization-defined
        frequency at the physical boundary of the facility or information
        system for unauthorized exfiltration of information or removal
        of information system components reflects organizational
        procedure/policy and is not applicable to
        HyperSphere configuration.

- control_key: PE-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employing guards and/or alarms to monitor every physical access
        point to the facility where the information system resides 24 hours
        per day, 7 days per week, reflects organizational procedure/policy and
        is outside the scope of HyperSphere configuration.

- control_key: PE-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Using lockable physical casings to protect organization-defined
        information system components from unauthorized physical access
        reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PE-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employing organization-defined security safeguards to
        detect and/or prevent physical tampering or alteration of
        organization-defined hardware components within the information
        system reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PE-3 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CA-8.

- control_key: PE-3 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Limiting access using physical barriers is outside the scope of
        HyperSphere configuration.

- control_key: PE-3 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Employment of access control vestibules is outside the scope of
        HyperSphere configuration.

- control_key: PE-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Controlling physical access to organization-defined information
        system distribution and transmission lines within organizational
        facilities using organizaiton-defined security safeguards reflects
        organizational procedure/policy and is not applicable to
        HyperSphere configuration.

- control_key: PE-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Controlling physical access to information system output devices to
        prevent unauthorized individuals from obtaining the output reflects
        organizational policy/procedures and is not applicable to
        HyperSphere configuration.

- control_key: PE-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PE-5.

- control_key: PE-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Linking individual identity to receipt of output from output devices
        is outside the scope of HyperSphere configuration.

- control_key: PE-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PE-22.

- control_key: PE-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Monitoring physical access to the facility where the information
        system resides to detect and respond to physical security incidents
        reflects organizational procedure/policy and is outside the scope
        of HyperSphere configuration.
    - key: b
      text: |
        Reviewing physical access logs at an organization-defined
        frequency and upon occurence of organization-defined events
        or potential indications of events, reflects organizational
        procedure/policy and is outside the scope of HyperSphere
        configuration.
    - key: c
      text: |
        Coordinating results of reviews and investigations with
        the organizational incident response capability reflects
        organizational procedure/policy and is not applicable to
        HyperSphere configuration.

- control_key: PE-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        Monitoring physical intrusion alarms and surveillance
        equipment reflects organizational procedure/policy and is
        not applicable to HyperSphere configuration.

- control_key: PE-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Employing video surveillance is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        Review of video recorgings is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        Retaining video recordings is outside the scope of HyperSphere configuration.


- control_key: PE-6 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PE-2 and PE-3.

- control_key: PE-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was wthdrawn by NIST and incorporated into PE-2.

- control_key: PE-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-11 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-13 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-13 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-13 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PE-13(2).

- control_key: PE-13 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-14 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-14 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-15 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.
        
- control_key: PE-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-18
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-18 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PE-23.

- control_key: PE-19
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-19 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-20
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-21
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-22
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.

- control_key: PE-23
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control is outside the scope of HyperSphere configuration.
##
## BEGINNING OF:
## PLANNING
##

- control_key: PL-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PL-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PL-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PL-7.

- control_key: PL-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PL-8.

- control_key: PL-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PL-2.

- control_key: PL-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PL-3.

- control_key: PL-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PL-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PL-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into RA-8.

- control_key: PL-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PL-2.

- control_key: PL-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned.
    - key: b
      text: |
        A control response is planned.

- control_key: PL-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
  narrative:
    - key: a
      text: |
        A control response is planned.
    - key: b
      text: |
        A control response is planned.
    - key: c
      text: |
        A control response is planned.

- control_key: PL-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PL-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PL-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PL-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: PL-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

##
## BEGINNING OF:
## PROGRAM MANAGEMENT
##

- control_key: PM-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-16 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-18
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-19
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-20
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-20 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.


- control_key: PM-21
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-22
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-23
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-24
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-25
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-26
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: e
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-27
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-28
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-28
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-29
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
        
- control_key: PM-30
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-30 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-31
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: b
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: c
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: d
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: e
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
    - key: f
      text: |
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.

- control_key: PM-32
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |-
        This control reflects organizational procedure/policy and is not
        applicable to HyperSphere configuration.
##
## BEGINNING OF:
## PERSONNEL SECURITY
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none

- control_key: PS-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PS-3.

- control_key: PS-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: PS-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PS-3.##
## BEGINNING OF:
## RISK ASSESSMENT
##

- control_key: RA-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        Organizational development, documentation, and dissemination to
        organization-defined personnel or roles a risk assessment policy
        and procedures is outside the scope of HyperSphere configuration.
    - key: a.1
      text: |
        Organizational development, documentation, and dissemination to
        organization-defined personnel or roles a risk assessment policy
        and procedures is outside the scope of HyperSphere configuration.
    - key: a.2
      text: |
        Organizational development, documentation, and dissemination to
        organization-defined personnel or roles a risk assessment policy
        and procedures is outside the scope of HyperSphere configuration.
    - key: b
      text: |
        Organizational review and updates to the risk assessment policy
        and risk assessment procedures is outside the scope of
        HyperSphere configuration.
    - key: b.1
      text: |
        Organizational review and updates to the risk assessment policy
        and risk assessment procedures is outside the scope of
        HyperSphere configuration.
    - key: b.2
      text: |
        Organizational review and updates to the risk assessment policy
        and risk assessment procedures is outside the scope of
        HyperSphere configuration.
    - key: c
      text: |
        Organizational review and updates to the risk assessment policy
        and risk assessment procedures is outside the scope of
        HyperSphere configuration.
    - key: c.1
      text: |
        Organizational review and updates to the risk assessment policy
        and risk assessment procedures is outside the scope of
        HyperSphere configuration.
    - key: c.2
      text: |
        Organizational review and updates to the risk assessment policy
        and risk assessment procedures is outside the scope of
        HyperSphere configuration.

- control_key: RA-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: f
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
      
- control_key: RA-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into RA-3.

- control_key: RA-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        HyperSphere currently does not have a CVE or errata stream to monitor and use for the basis
        of vulnerability scans. This capability is planned for a future release.
    - key: b
      text: |
        HyperSphere currently does not have a CVE or errata stream to monitor and use for the basis
        of vulnerability scans. This capability is planned for a future release.

        In the spirit of RA-5(b), a standards-based approach using SCAP and OVAL is planned.
    - key: c
      text: |
        HyperSphere currently does not have a CVE or errata stream to monitor and use for the basis
        of vulnerability scans. This capability is planned for a future release.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        HyperSphere currently does not have a CVE or errata stream to monitor and use for the basis
        of vulnerability scans. This capability is planned for a future release.
    - key: f
      text: |
        HyperSphere currently does not have a CVE or errata stream to monitor and use for the basis
        of vulnerability scans. This capability is planned for a future release.

- control_key: RA-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into RA-5.

- control_key: RA-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        HyperSphere currently does not have a CVE or errata stream to monitor and use for the basis
        of vulnerability scans. This capability is planned for a future release.

- control_key: RA-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        HyperSphere currently does not have a CVE or errata stream to monitor and use for the basis
        of vulnerability scans. This capability is planned for a future release.

- control_key: RA-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response is planned.

- control_key: RA-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        Currently HyperSphere does not have a RBAC capability. This is planned for a future release.

- control_key: RA-5 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-5 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-8.

- control_key: RA-5 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-5 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-8.

- control_key: RA-5 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: RA-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A criticality analysis of HyperSphere components is planned.

- control_key: RA-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.##
## BEGINNING OF:
## SYSTEM AND SERVICES ACQUISITION
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none


- control_key: SA-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: f
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: g
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: h
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: i
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is undergoing the process to publish a NIST National Checklist for HyperSphere,
        which will include a description of the functional properties of the controls to be
        implemented.

- control_key: SA-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is undergoing the process to publish a NIST National Checklist for HyperSphere,
        which will include system interfaces, high and low-level design, and other materials
        to satisfy this control.

- control_key: SA-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        Documentation regarding HyperSphere systems engineering methods is planned.
    - key: b
      text: |
        Documentation regarding HyperSphere systems security, privact, and engineering methods, is
        planned.
    - key: c
      text: |
        Documentation regarding HyperSphere software development methods, testing, evaluation,
        and other materials to satisfy this control, is planned.

- control_key: SA-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-8(9).

- control_key: SA-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere is in the process of developing a NIST National Checklist for HyperSphere,
        which will outline the security configurations and implementation details of those
        configurations.
    - key: b
      text: |
        HyperSphere is in the process of developing a NIST National Checklist for HyperSphere,
        which will outline the security configurations and implementation details of those
        configurations.

- control_key: SA-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere is not currently an NSA-approved solution to protect classified
        information. These certifications and approvals are planned.
    - key: b
      text: |
        HyperSphere is not currently an NSA-approved solution to protect classified
        information. These certifications and approvals are planned.

##
## Developers note on SA-4 (7):
##  As of 2018, protection profiles recognized by NIAP and those recognized
##  by the broader Common Criteria effort have diverged. A listing of NIAP-
##  recognized protection profiles can be found here:
##
##  https://www.niap-ccevs.org/Profile/PP.cfm
##
- control_key: SA-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere has not completed an evaluation against a NIAP-approved
        protection profile. This is under consideration for a future release.
    - key: b
      text: |
        HyperSphere's cryptographic functions are not FIPS-validated nor
        NSA-approved. This is under consideration for a future release.

##
## Developers note on SA-4 (8):
##  A successful control response will document how to achieve continuous
##  monitoring of control/standards as identified in CA-7.
##
- control_key: SA-4 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        As part of the NIST National Checklist for HyperSphere, currently the
        intent is to release SCAP content for HyperSphere which can be consumed by any
        NIST-validated SCAP scanner.

##
## Developers note on SA-4 (9):
##  A successful control response will document all network
##  information. Take care to document internal network usage,
##  including loopback devices, as it is customary to block all
##  traffic not explicitly outlined in this control.
##
- control_key: SA-4 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Documentation regarding HyperSphere's functions, ports, protocols, and services,
        is under development for a future release.

- control_key: SA-4 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere does not support PIV-based authentication. This is default,
        non-configurable, behavior. HyperSphere cannot be configured to be out of
        compliance with this control.

  control_key: SA-4 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-4 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    
- control_key: SA-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        Administrator documentation for HyperSphere is under development.
    - key: a.1
      text: |
        A secure configuration guide for HyperSphere is under development.
    - key: a.2
      text: |
        A maintenance guide for HyperSphere is under development.
    - key: a.3
      text: |
        A known vulnerability catalog for HyperSphere is under development.
    - key: b
      text: |
        Documentation regarding user-accessible security functions is under
        development.
    - key: b.1
      text: |
        A secure configuration guide for HyperSphere is under development.
    - key: b.2
      text: |
        A user guide for HyperSphere is under development.
    - key: b.3
      text: |
        A user guide for HyperSphere is under development.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    
- control_key: SA-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-4(1).

- control_key: SA-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-4(2).

- control_key: SA-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-4(2).

- control_key: SA-5 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-4(2).

- control_key: SA-5 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-4(2).

- control_key: SA-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-10 and SI-7.

- control_key: SA-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into CM-11 and SI-7.

- control_key: SA-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere does not include shared mechanisms. This is default, non-configurable, behavior.
        HyperSphere cannot be configured to be out of compliance with this control.

- control_key: SA-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is addressing this control through development of a Type Enforcement (SELinux)
        policy. This will ensure modular decomposition of HyperSphere into network accesses,
        separation of HyperSphere components into processes with distinct security policies,
        and separation of HyperSphere with distinct privileges to hardware as needed.

- control_key: SA-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-8 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        The ability to deploy HyperSphere via trusted computing mechanisms, such as TEE, is
        planned.

- control_key: SA-8 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere supports the security design principle of minimized sharing by
        being fully supported in virtual environments.

- control_key: SA-8 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere supports the security design principle of reduced complexity through its
        software architecture. HyperSphere has been designed as simple and small as possible.
        This is default, non-configurable, behavior. HyperSphere cannot be configured to be
        out of compliance with this control.

- control_key: SA-8 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is addressing the security design principle of secure evolvability
        by creating SCAP content, which can be dynamically tuned per mission need, and
        by creating SELinux policies, which can also be dynamically adjusted per mission need.

- control_key: SA-8 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        The ability to deploy HyperSphere via trusted computing mechanisms, such as TEE, is
        planned.

- control_key: SA-8 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is addressing this control through development of a Type Enforcement (SELinux)
        policy. This will ensure HyperSphere adheres to the Bell-LaPadula model.

- control_key: SA-8 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        The principle of inverse modification threshold is not yet implemented in HyperSphere.

- control_key: SA-8 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        The principle of hiearchical protection is not yet implemented in HyperSphere.

- control_key: SA-8 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        The principle of hiearchical protection is not yet implemented in HyperSphere.

- control_key: SA-8 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        The HyperSphere role-based access control subsystem implements the concept of least
        privilege. This is default, non-configurable, behavior. HyperSphere cannot be configured
        to be out of compliance with this control.

- control_key: SA-8 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        The principle of predicate permission is not yet implemented in HyperSphere.

- control_key: SA-8 (16)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere implements security mechanisms dependent on other system components,
        and thus cannot satisfy this control. For example, HyperSphere depends on file permissions
        from the operating system, from cryptographic random number generation from underlying
        operating system libraries, etc. The fundamental trust of HyperSphere is dependent
        on being deployed on a trusted compute platform.

- control_key: SA-8 (17)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (18)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (19)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (20)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (21)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (22)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (23)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (24)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (25)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (26)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (27)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (28)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (29)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (30)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (31)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (32)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-8 (33)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SA-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-9 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-9 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-9 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-9 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-9 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-9 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-9 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-9 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

##
## Developers note on SA-10
##  A successful control response will document all network
##  information. Take care to document internal network usage,
##  including loopback devices, as it is customary to block all
##  traffic not explicitly outlined in this control.
##
- control_key: SA-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    ## A successful control response will document performance of configuration
    ## management. Processes and mechanisms involved in configuration management
    ## will need to be addressed.
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

    ## A successful control response will need to address the processes
    ## and mechanisms involved in documenting, managing, and controlling the
    ## integrity of chances.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

    ## A successful control response will need to address the approval process
    ## and safeguards in place to ensure only approved changes are implemented.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

    ## A successful control response will need to discuss the process for
    ## documentation.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

    ## A successful control response will need to discuss the process
    ## and tools used for tracking, resolution, and reporting.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

##
## Developers note on SA-10 (1)
##  A successful control response will need to address the process and
##  mechanisms involved in integrity verification.
##
##  For example, TPM+TXT for hardware and operating systems.
##
- control_key: SA-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently does not cryptographically sign installation media. This is
        planned for a future release.

- control_key: SA-10 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

##
## Developers note on SA-10 (3)
##  This control differs from SA-10 (1) by focusing on hardware
##  (vs software and firmware).
##
##  This control may not be applicable if the component being documented
##  is not involved in the system boot process.
##
- control_key: SA-10 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

##
## Developers note on SA-10 (4)
##  This control may not be applicable if the component being documented
##  is not involved in the system boot process.
##
- control_key: SA-10 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere maintains secure version control over internal source code. This is
        default, non-configurable, behavior. HyperSphere cannot be configured to be out of
        compliance with this control.

- control_key: SA-10 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-10 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently does not cryptographically sign installation media. This is
        planned for a future release.

- control_key: SA-10 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    ## A successful control response will need to outline the security
    ## assessment plan.
    - key: a
      text: |
        HyperSphere is evaluating the evolution of its CI/CD system to embed
        testing of technical NIST controls, as appropriate. This is being evaluated
        for inclusion in a future release.
    - key: b
      text: |
        HyperSphere is in the process of evolving its unit testing and integration system.

    ## A successful control response will need to address the process by
    ## which the customer obtains and reviews the evidence and results of
    ## testing.
    - key: c
      text: |
        HyperSphere is in the process of evolving its unit testing and integration system.

    ## A successful control response will need to outline the means by which
    ## flaws are identified and addressed.
    - key: d
      text: |
        HyperSphere is in the process of estagblishing a flaw remediation process.

    ## A successful control response will need to discuss the procedure for
    ## identifying flaws, alerting appropriate personnel to correct flaws, and
    ## verifying the success of the correction.
    - key: e
      text: |
        HyperSphere corrects flaws identified during internal testing and evaluation.
        This is default, non-configurable, behevior. HyperSphere cannot be configured
        to be out of compliance with this control.

##
## Developers note on SA-11 (1)
##  A successful control response will document how static code analysis
##  tools are used on this compont to identify of common flaws,
##  and how the results of the analysis are integrated into actions.
##
- control_key: SA-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is in the process of evolving its CI/CD system, and
        plans to include static code analysis.

##
## Developers note on SA-11 (2)
##  A successful control response will need to address the analysis
##  of how the as-built system differs from the initial design, as well
##  as how any new vulnerabilities created as a result of these differences
##  are reviewed and mitigated.
##
- control_key: SA-11 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: b
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: c
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: d
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-11 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: b
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-11 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-11 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: b
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-11 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-11 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-11 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into the SR family.

- control_key: SA-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-5.

- control_key: SA-12 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-6.

- control_key: SA-12 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SR-3.

- control_key: SA-12 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-3(1).

- control_key: SA-12 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-3(2).

- control_key: SA-12 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-5(11).

- control_key: SA-12 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-5(2).

- control_key: SA-12 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into RA-3(2).

- control_key: SA-12 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-7.

- control_key: SA-12 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-4(3).

- control_key: SA-12 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-6(1).

- control_key: SA-12 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-8.

- control_key: SA-12 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to MA-6 and RA-9.

- control_key: SA-12 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-4(1) and SR-4(2).

- control_key: SA-12 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SR-3.

- control_key: SA-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-8.

- control_key: SA-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into RA-9.

- control_key: SA-14 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-20.

- control_key: SA-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere is currently developing a plan that explicitly addresses security
        and privacy requirements.
    - key: a.1
      text: |
        HyperSphere is currently developing a plan that explicitly addresses the security
        and privacy requirements.
    - key: a.2
      text: |
        HyperSphere is currently developing documentation that identifies the standards and tools
        used in the development process.
    - key: a.3
      text: |
        HyperSphere is currently documenting the specific tool options and tool configurations
        used in the development process.
    - key: a.4
      text: |
        HyperSphere is currently developing documentation that outlines the integrity control
        of changes to the process and/or tools used in development.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-15 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: b
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-15 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-15 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere is currently undergoing a criticality analysis which will be published
        at a later date.
    - key: b
      text: |
        HyperSphere is currently undergoing a criticality analysis which will be published at
        a later date.

- control_key: SA-15 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-11(2).

- control_key: SA-15 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-15 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-15 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: b
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: c
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: d
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-15 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-15 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-3(2).

- control_key: SA-15 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-15 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-15 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently does not offer training.

- control_key: SA-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere is currently developing a design specification and
        security and privacy architecture for inclusion in a future release.
    - key: b
      text: |
        HyperSphere is currently developing a design specification and
        security and privacy architecture for inclusion in a future release.
    - key: c
      text: |
        HyperSphere is currently developing a design specification and
        security and privacy architecture for inclusion in a future release.

- control_key: SA-17 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: b
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-17 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: b
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-17 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: b
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: c
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: d
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: e
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-17 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: b
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: c
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: d
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: e
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-17 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.
    - key: b
      text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-17 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-17 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-17 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-17 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-18
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-9.

- control_key: SA-18 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-9(1).

- control_key: SA-18 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-10.

- control_key: SA-19
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-11.

- control_key: SA-19 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-11(1).

- control_key: SA-19 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-11(2).

- control_key: SA-19 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-12.

- control_key: SA-19 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SR-11(3).

- control_key: SA-20
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any Federal baseline. This control will be
        evaluated in future versions of the NIST National Checklist for HyperSphere.

- control_key: SA-21
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-22
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SA-22 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-22.

- control_key: SA-23
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SA-22.
##
## BEGINNING OF:
## SYSTEMS AND COMMUNICATIONS PROTECTION
##

- control_key: SC-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        A Role-Based Access Control system is being implemented which will
        separate user functionality from system management functionality.

- control_key: SC-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere is classified as non-kernel code, and utilizes file system
        protections that protect HyperSphere on disk, and address space protections are
        utilized for compiled code, such as RELRO and NOEXEC.

        This is default, non-configurabe, behavior. HyperSphere cannot be configured to
        be out of compliance with this control.

- control_key: SC-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere does not provide shared system resources. This is default, non-configurable,
        behavior. HyperSphere cannot be configured to be out of compliance with this control.

- control_key: SC-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-4.

- control_key: SC-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere intends to implement a rate-limiting capability into the
        HyperSphere API, which will protect against and limit the effects of
        denial-of-service events.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-5 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-5 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.
    - key: b
      text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-7.

- control_key: SC-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-7.

- control_key: SC-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently does not enforce a limit on simultanious sessions. This
        capability is being reviewed for inclusion in a future version.

- control_key: SC-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: f
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: g
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: h
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-7(18).

- control_key: SC-7 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is in the process of documenting host-level firewall requirements.

- control_key: SC-7 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (16)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
       This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (17)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (18)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (19)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (20)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (21)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (22)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (23)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (24)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
        
- control_key: SC-7 (25)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (26)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (27)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (28)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-7 (29)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently, HyperSpere allows both HTTP and HTTPS connections. Future versions
        of HyperSphere will only allow TLS, which will protect the confidentiality and integrity
        of transmitted information.

- control_key: SC-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently, HyperSpere allows both HTTP and HTTPS connections. Future versions
        of HyperSphere will only allow TLS, which will protect the confidentiality and integrity
        of transmitted information.

- control_key: SC-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently, HyperSpere allows both HTTP and HTTPS connections. Future versions
        of HyperSphere will only allow TLS, which will protect the confidentiality and integrity
        of transmitted information.

- control_key: SC-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently, HyperSpere allows both HTTP and HTTPS connections. Future versions
        of HyperSphere will only allow TLS, which will protect the confidentiality and integrity
        of transmitted information.

- control_key: SC-8 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently, HyperSpere allows both HTTP and HTTPS connections. Future versions
        of HyperSphere will only allow TLS, which will protect the confidentiality and integrity
        of transmitted information.

- control_key: SC-8 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently, HyperSpere allows both HTTP and HTTPS connections. Future versions
        of HyperSphere will only allow TLS, which will protect the confidentiality and integrity
        of transmitted information.

- control_key: SC-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-8.

- control_key: SC-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere terminates connections at the end of the session. This is default,
        non-configurable, behavior. HyperSphere cannot be configured to be out of compliance
        with this control.

- control_key: SC-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.
    - key: b
      text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-11 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - key: a
      text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.
    - key: b
      text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere utilizes operating system provided OpenSSL libraries
        for the generation of cryptographic keys. This behavior is hard-coded
        into HyperSphere and is default, non-configurable, behavior. HyperSphere
        cannot be configured to be out of compliance with this control.

- control_key: SC-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        In the event of the loss of cryptographic keys, HyperSphere users
        will be unable to revive their data.

- control_key: SC-12 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently allows for the use of non-FIPS and non-NSA approved
        key management technology. These options are being considered for removal in
        future HyperSphere versions.

- control_key: SC-12 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        HyperSphere does not produce, control, or distribute, asymmetric keys. HyperSphere
        exclusively uses symetric encryption. This is default, non-configurable, behavior. HyperSphere
        cannot be confitured to use asymmetric keys.

- control_key: SC-12 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-12(3).

- control_key: SC-12 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SC-12(3).

- control_key: SC-12 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A complete control response regarding the cryptographic uses of HyperSphere is planned.
    - key: b
      text: |
        A complete control response regarding the types of cryptography available in HyperSphere
        is planned.

- control_key: SC-13 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-13.

- control_key: SC-13 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-13.

- control_key: SC-13 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-13.

- control_key: SC-13 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-13.

- control_key: SC-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AC-2,
        AC-3, AC-5, AC-6, SI-3, SI-4, SI-5, SI-7, and SI-10.

- control_key: SC-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-15 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-15 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-7.

- control_key: SC-15 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-15 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-16 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-16 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-16 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unknown
  narrative:
    - text: |
        This NIST control is not selected in any federal baseline. A control response is
        not available at this time.

- control_key: SC-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-18
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-18 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-18 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-18 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-18 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-18 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-19
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST as technology-specific; addressed
        as any other technology or protocol.

- control_key: SC-20
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-20 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-20.

- control_key: SC-20 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-21
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-21 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-21.

- control_key: SC-22
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-23
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently HyperSphere allows for both HTTP and HTTPS connections.
        Future versions of HyperSphere plan to enable TLS by default.

- control_key: SC-23 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        Once a HyperSphere session is terminated, all session identifiers are invalidated.
        This is default, non-configurable, behavior. HyperSphere cannot be configured to be
        out of compliance with this control.

- control_key: SC-23 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AC-12 (1).

- control_key: SC-23 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        All sessions to HyperSphere are uniquely generated and HyperSphere only
        recognizes sessions that are system-generated. This is default, non-configurable,
        behavior. HyperSphere cannot be configured to be out of compliance with this
        control.

- control_key: SC-23 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-23(3).

- control_key: SC-23 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-24
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere does not currently fail to a known system state. This functionality
        is being reviewed for inclusion in a future HyperSphere release.

- control_key: SC-25
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-26
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-26 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-35.

- control_key: SC-27
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-28
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned on how HyperSpher Vault protects
        data at rest.

- control_key: SC-28 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned on how HyperSpher Vault protects
        data at rest.

- control_key: SC-28 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-28 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A complete control response is planned on how HyperSpher Vault protects
        the cryptographic keys used.

- control_key: SC-29
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-29 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-30
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-30 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-29(1).

- control_key: SC-30 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-30 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently, HyperSphere does not change the location of storage. This capability is being
        evaluated for inclusion in a future release.

- control_key: SC-30 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-30 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-31
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-31 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-31 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-31 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-32
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-32 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-33
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SC-8.

- control_key: SC-34
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-34 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-34 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-34 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to SC-51.

- control_key: SC-35
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-36
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-36 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere does not currently employ techniques to identify potential faults, errors,
        or compromises to the storage components.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-36 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-37
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently does not support out-of-band transmission of HyperSphere binaries.
        This is being evaluated for inclusion in future releases.

- control_key: SC-37 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-38
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-39
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        HyperSphere is currently in the process of authoring SELinux policies for HyperSphere.
        These will be included in a future release.

- control_key: SC-39 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

# TO DO: This is playing to the edge of what the control intends. Good enough for now, 
# but we will want to elaborate later.
- control_key: SC-39 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere utilizes Erlang/Elixir, which maintains separate execution domains for each
        thread. This is default, non-configurable, behavior. HyperSphere cannot be configured to be
        out of compliance with this control.

- control_key: SC-40
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-40 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-40 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-40 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-40 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-41
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-42
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-42 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-42 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-42 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-42 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-42 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-43
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-44
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-45
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-45 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-45 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-46
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-47
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-48
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-48 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-49
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-50
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SC-51
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.##
## BEGINNING OF:
## SYSTEM AND INFORMATION INTEGRITY
##
## Reminder of "implementation_status" codes:
##  - implementation_status: unsatisfied
##  - implementation_status: unknown
##  - implementation_status: planned
##  - implementation_status: partial
##  - implementation_status: complete
##  - implementation_status: none


- control_key: SI-1
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration

- control_key: SI-2
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-2 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into PL-9.

- control_key: SI-2 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently does not have the capability to support automated mechanisms to determine
        if HyperSphere has applicable security-relevant software updates installed. 

        Future releases of HyperSphere will include installation via native package managers, such as
        RPM on Red Hat Enterprise Linux-based hosts. This will aide in the automated evaluation of patches.

- control_key: SI-2 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere currently does not publish vulnerability information such as flaw identification and flaw remediation dates.
        As such, this control is a permanent finding when HyperSphere is used.

        Future releases of HyperSphere will include a vulnerability management feed, using standards such as SCAP OVAL and/or CVE,
        which will aide in satisfying this control.

    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-2 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently does not have the capability to support automated patch management tools. As such,
        this control is a permanent finding when HyperSphere is used.

        Future releases of HyperSphere plan to introduce native package management systems, such as RPM on Red Hat Enterprise Linux,
        which will aide in resolution of this control.

- control_key: SI-2 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently does not have the capability to support automated patch mananagement tools. As such,
        this control is a permanent finding when HyperSphere is used.

        Future releases of HyperSphere plan to introduce native package management systems, such as RPM on Red Hat Enterprise Linux,
        which will aide in resolution of this control.

- control_key: SI-2 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-3
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-3 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
       This control was withdrawn by NIST and incorporated into PL-9.

- control_key: SI-3 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SI-3.

- control_key: SI-3 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AC-6(10).

- control_key: SI-3 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-3 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into MP-7.

- control_key: SI-3 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-3 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SI-3.

- control_key: SI-3 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.


- control_key: SI-3 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to AC-17

- control_key: SI-3 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: a.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.1
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c.2
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: e
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: f
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: g
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response outlining recommendations for criteria for unusual or unauthorized activities
        or conditions for inbound and outbound communications traffic to HyperSphere is planned.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.


- control_key: SI-4 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently lacks an audit or log management capability.

        Future versions of HyperSphere will include an audit subsystem, which will aide in
        addressing this control.

- control_key: SI-4 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into AC-6(10).

- control_key: SI-4 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere currently lacks an audit or log management capability. As a result, HyperSphere cannot identify
        suspicious events, nor is it possible to forward events (e.g. remote syslog) to a centralized SIEM for
        further analysis.

        Future versions of HyperSphere will include an audit subsystem, which will aide in addressing this
        control.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SI-4.

- control_key: SI-4 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently lacks an audit or log management capability. As a result, HyperSphere cannot identify
        suspicious events, nor is it possible to forward events (e.g. remote syslog) to a centralized SIEM for
        further analysis.

        Future versions of HyperSphere will include an audit subsystem, which will aide in addressing this
        control.

- control_key: SI-4 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (16)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently lacks an audit or log management capability. As a result, HyperSphere cannot identify
        suspicious events, nor is it possible to forward events (e.g. remote syslog) to a centralized SIEM for
        further analysis.

        Future versions of HyperSphere will include an audit subsystem, which will aide in addressing this
        control.

- control_key: SI-4 (17)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (18)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (19)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (20)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently lacks an audit or log management capability. As a result, HyperSphere cannot implement additional
        monitoring of privileged users interfacing with HyperSphere.

        Future versions of HyperSphere will include an audit subsystem, which will aide in addressing this
        control.

- control_key: SI-4 (21)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently lacks an audit or log management capability. As a result, HyperSphere cannot implement additional
        monitoring of individuals or applications interfacing with HyperSphere.

        Future versions of HyperSphere will include an audit subsystem, which will aide in addressing this
        control.

- control_key: SI-4 (22)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (23)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (24)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-4 (25)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-5
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-5 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-6
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: c
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: d
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-6 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SI-6.

- control_key: SI-6 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-6 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-7
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is currently installed directly onto endpoints. Future versions of HyperSphere
        will have cryptographically signed packages and binaries, which will allow users to employ
        integrity verification tools (e.g. checksums) of HyperSphere software.

- control_key: SI-7 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is currently installed directly onto endpoints. Future versions of HyperSphere
        will have cryptographically signed packages and binaries, which will allow users to employ
        integrity verification tools (e.g. checksums) of HyperSphere software.

- control_key: SI-7 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is currently installed directly onto endpoints. Future versions of HyperSphere
        will have cryptographically signed packages and binaries, which will allow users to employ
        integrity verification tools (e.g. checksums) of HyperSphere software.

- control_key: SI-7 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-7 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST, and incorporated into SR-9.

- control_key: SI-7 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-7 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is currently installed directly onto endpoints. Future versions of HyperSphere
        will have cryptographically signed packages and binaries, which will allow users to employ
        integrity verification tools (e.g. checksums) of HyperSphere software.

- control_key: SI-7 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-7 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.
        
- control_key: SI-7 (9)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-7 (10)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-7 (11)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to CM-7(6).

- control_key: SI-7 (12)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is currently installed directly onto endpoints. Future versions of HyperSphere
        will have cryptographically signed packages and binaries, which will allow users to employ
        integrity verification tools (e.g. checksums) of HyperSphere software.

- control_key: SI-7 (13)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to CM-7(7).

- control_key: SI-7 (14)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and moved to CM-7(8).

- control_key: SI-7 (15)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere is currently installed directly onto endpoints. Future versions of HyperSphere
        will have cryptographically signed packages and binaries, which will allow users to employ
        integrity verification tools (e.g. checksums) of HyperSphere software.

- control_key: SI-7 (16)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-7 (17)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Future versions of HyperSphere plan to include SELinux policies, which will aide
        in resolution of this control.

- control_key: SI-8
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-8 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated in PL-9.

- control_key: SI-8 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-8 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-9
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into AC-2, AC-3, AC-5, and AC-6.

- control_key: SI-10
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - text: |
        A control response outlining how HyperSpher validates inputs is planned.

- control_key: SI-10 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - key: a
      text: |
        HyperSphere does not have a manual override for input validation.
    - key: d
      text: |
        HyperSphere does not have a manual override for input validation. As such, its usage
        cannot be restricted.
    - key: c
      text: |
        HyperSphere does not have a manual override for input validation. As such, its use cannot be audited.

- control_key: SI-10 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere does not offer an SLA on when bugs, such as input validation errors, will be
        addressed.

- control_key: SI-10 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Future versions of HyperSphere intent to integrate native fuzzing technology, which will aide
        in the resolution of this control.

- control_key: SI-10 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: complete
  narrative:
    - text: |
        HyperSphere utilizes the native time service of the host operating system to account for timing
        interactions. This is default, non-configurable, behavior. HyperSphere cannot be configured to
        be out of compliance with this control.

- control_key: SI-10 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Current versions of HyperSphere allow for any object ("input") to be encrypted. The ability to restrict objects
        is being considered for a future release.

- control_key: SI-10 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Parameterized interfaces is being considered for inclusion in future versions of HyperSphere.

- control_key: SI-11
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisified
  narrative:
    - key: a
      text: |
        Custom error messages is being considered for inclusion in future HyperSphere releases.
    - key: b
      text: |
        The ability to reveal error messages only to organization-defined personnel or roles is being evaluated for
        inclusion in a future HyperSphere release.

- control_key: SI-12
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-12 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-12 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-12 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-13
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-13 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-13 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This control was withdrawn by NIST and incorporated into SI-7(6).

- control_key: SI-13 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-13 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-13 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-14
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Future HyperSphere versions will support session-based authentication, which will terminate upon end of session use, or
        periodically at an orgaization-defined frequency.

- control_key: SI-14 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        Currently HyperSphere does not have a standardized software distribution process. Future versions of HyperSphere will allow
        for attaining software from HyperSphere in a confidential manner with high integrity of the software.

- control_key: SI-14 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-14 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-15
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently does not provide output validation.

- control_key: SI-16
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: unsatisfied
  narrative:
    - text: |
        HyperSphere currently does not offer memory protections. Future versions will be compiled with memory safety flags.

- control_key: SI-17
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-18
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-18 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-18 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-18 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-18 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-19
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-19 (1)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-19 (2)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-19 (3)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-19 (4)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-19 (5)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-19 (6)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-19 (7)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-19 (8)
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-20
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-21
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-22
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: not applicable
  narrative:
    - key: a
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.
    - key: b
      text: |
        This is an organizational control outside the scope of HyperSphere configuration.

- control_key: SI-23
  standard_key: NIST-800-53
  covered_by: []
  implementation_status: planned
  narrative:
    - key: a
      text: |
        A control response is planned.
    - key: b
      text: |
        A control response is planned.
