Skip to content
Foxx Cyberfoxxcyber/docs

Control Implementations (SCTM)

Apply a baseline template to the SCTM, track compliance and continuous monitoring per control, and record CCI-level implementation responses in the package Catalog.

Control work in a package happens in two linked views. The SCTM (Security Controls Traceability Matrix) is the per-control ledger an assessor reads: applicability, type, responsibility, compliance status, ConMon frequency, evidence and validation method. The package Catalog is where the implementation itself is written, one CCI at a time, and the Catalog's status rolls up into the SCTM.

The reference catalog

Controls Catalog in the main sidebar is the read-only NIST SP 800-53 Rev 5 reference — "1,190 controls across 20 families". Family buttons (AC … SR, each with a count) filter the table of Control / Name with the full control text expanded per row. Nothing you do here touches a package; it is there to look things up.

The global Controls Catalog with family buttons and full control text

The SCTM

Open SCTM in the package sidebar. The page is titled Security Controls Traceability Matrix — Compliance, continuous monitoring, and validation tracking.

The SCTM with the applied Moderate template, compliance totals, family filters and the per-control columns

Apply a baseline template first

The SCTM is empty until a baseline template is applied. Click Apply Baseline Template. The dialog reads "Select a control baseline or overlay for this package. Existing tailoring and assessment data is preserved — conflicts are flagged, never overwritten." Pick a template from the combobox — NIST 800-53 Rev 5 High (522 controls), Moderate (297) or Low (126); the one matching the package's high-water mark is marked Recommended and preselected — and click Apply Template.

Applying is idempotent. If you change the package baseline later, use Apply / Re-apply Template in the SCTM header; tailoring and assessment data you have already entered is kept. The templates themselves are managed under Admin → Baseline Templates.

Reading the matrix

The header shows the applied template badge (for example NIST 800-53 Rev 5 Moderate v1), the Baseline controls only switch, and totals: Total, Applicable, Compliant (green), Non-Compliant (red), Tailored Out. Family buttons show compliant / catalog size for that family (ALL 0/1190, AC 0/147 …). Filters: applicable (applicable / all / N/A), all (type), Search controls…, and a "36 of 36" style count of rows currently shown.

ColumnWhat it holds
CONTROLThe control ID; the link opens the package Catalog for that family
NAMEControl title
N/ATailor Out (mark N/A) — removes the control from the applicable set with a justification
TYPE—, Inherited, System-Specific, Hybrid or Common
RESPONSIBLEAssign… a person
COMPLIANCENot Assessed, Compliant, Partial or Non-Compliant
STIGDerived from imported checklist findings — see STIG posture; you do not edit it
CONMON FREQContinuous, Daily, Weekly, Monthly, Quarterly, Semi-Annual or Annual
EVID.Count badge of mapped evidence
VALIDATIONExamine / Interview / Test icons — the assessment methods

Compliance is an assessment statement, not an implementation statement

COMPLIANCE in the SCTM is what you assert to the authorizing official. The implementation narrative that backs it up lives in the package Catalog below, at CCI level. Keep both current: an SCTM row marked Compliant with no CCI responses will not survive an assessor's first question.

CCI-level responses in the package Catalog

Open Catalog in the package sidebar (or click a control in the SCTM). The page is titled Controls Catalog — NIST 800-53 Rev 5 control implementation status and CCI-level responses, with totals Controls / Implemented / Partial / Not Implemented, the family buttons and Filter controls….

The package Catalog with AC-2 expanded to its CCI list and the response editor for one CCI

The table shows Control, Name, CCIs (count badge), Status (Not Implemented / Partial / Implemented — derived from the CCI responses) and Assessment. Click a row to expand it inline: the badge and name, CONTROL TEXT, DISCUSSION, then the CCI list.

Each CCI row (CCI-000010, a status pill and the requirement text) expands to the response editor:

  • COMPLIANCE STATUS — Not Implemented, Planned, Partial, Implemented or N/A
  • LIKELIHOOD and IMPACT — Very Low, Low, Moderate, High, Very High
  • RISK LEVEL — computed from likelihood and impact, read-only
  • IMPLEMENTATION RESPONSE — "Describe how this CCI requirement is met…"; this is the sentence that ends up in the SSP
  • MITIGATION NOTES — "Risk mitigation strategies, compensating controls…"
  • EVIDENCE (n) with + Link Evidence
  • Save — disabled until something changed

A control only reads Implemented when all of its CCIs are. A control with 35 CCIs and 3 answered still shows Not Implemented, and the family counts in the SCTM reflect that.

Work family by family

Use the family buttons to work one family at a time, and the Filter controls… box to jump to a specific control. Every saved response is an entry in the package Activity log ("updated Implementation (complianceStatus)"), so a reviewer can see when each CCI was last touched.

Last updated August 27, 2026