Admin

Admin · Governance · Frameworks

Frameworks, mapped.

The compliance frameworks the federation control plane maps to, each backed by control-level coverage. ISO 27001 is bound to the provider cert string so the register reads one source of truth, and the full evidence pack exports for an auditor without rebuilding it.

Frameworks32 on track
Controls passing7of 10 total
Controls at attention2warn or failing
Cert-linked1bound to provider cert

Framework register

coverage · cert-bound

SOC 2 Type IIon-track

Trust services criteria for the federation control plane.

last assessed 2026-06-30

Control coverage3/4 passing · 75%1 at attention
Controls for SOC 2 Type II, with status and evidence.
ControlStatusEvidence
CC7.2Incident responsepassing
  • INC-1 runbook
  • EVT-9926 break-glass ledger
CC8.1Change managementpassing
  • CHG-5121 policy gate
  • soc2-change enforcement
CC6.1Logical accesswarn
  • MFA enrollment 83%
  • u-nw-ops pending
CC6.6Break-glass approvalpassing
  • BG-2201 approved
  • dual-signoff

ISO/IEC 27001on-track

Information security management system controls.

last assessed 2026-05-15

Control coverage2/3 passing · 67%

certISO 27001held by Meridian Capacity Co.

Controls for ISO/IEC 27001, with status and evidence.
ControlStatusEvidence
A.9Access controlpassing
  • RBAC catalog
  • least-privilege review
A.12.1Operational changepassing
  • change gates enforced
A.18.1Sovereign data residencymanual
  • Meridian sovereign-ready
  • exit plan tested

HIPAA (Briarcliff scope)at-risk

PHI handling for the Briarcliff Health custodial engagement.

last assessed 2026-04-20

Control coverage2/3 passing · 67%1 at attention
Controls for HIPAA (Briarcliff scope), with status and evidence.
ControlStatusEvidence
164.312(a)Access control (PHI)passing
  • PHI-isolated data plane
  • BAA on file
164.308(a)Workforce securitywarn
  • u-bc-admin MFA not enrolled
164.502(e)Business associatepassing
  • BAA cert valid