Real World Careers

SSP-RWC-FED-2026-08-29 · FIPS 199 Low · not an ATO

System Security Plan (lite).

Short control narrative for Federal Fit Scale ($14,500 / 290 seats). Architecture detail lives on the security statement. Data roles live on the DPA. FedRAMP is not authorized. The buying agency remains the authorizing official for its own use.

1. System identification

FieldValue
Information systemReal World Careers Federal Fit (commercial SaaS)
System ownerAdvanced Learning Academy LLC · UEI Z272LH7MCDT2 · CAGE 1A8H4
Location1950 E Greyhound Pass, Carmel, IN 46033 · cloud: Cloudflare (United States)
Public originhttps://realworldcareers.com
FIPS 199 (this SKU)Confidentiality Low · Integrity Low · Availability Low — if the agency stores only Employer Worker IDs and scores, not SSN, not classified, not CUI
CUINot intended. If the agency designates the file as CUI, this SKU is the wrong system
FedRAMPNot authorized. Cloudflare’s platform has its own authorizations; they do not confer an ATO on this customer SaaS
GSA ScheduleNone
POCTimothy E. Parker, CEO · team@advancedlearning.academy · 1-317-751-5444

2. Authorization boundary

  1. Agency admin types Employer Worker IDs (not names, not SSN) into numbered seats.
  2. Participant opens a unique HTTPS invite, answers 50 items in the browser.
  3. Cloudflare Worker scores the session. D1 stores credential, scores, completion metadata.
  4. Agency retrieves HTML reports and CSV over HTTPS. Agency owns the export.
  5. Stripe processes the card (or the agency invoices Net 30 ACH). Mailgun sends transactional mail if ALA is asked to mail invites — default is the agency sends access in its own mail.

No on-prem agent. No mobile-app binary. No PIV/SSO in this SKU. Subprocessors: Cloudflare (compute/storage/DNS/WAF), Stripe (payments), Mailgun/Sinch (email). Detail: security.html.

3. Control implementation (NIST SP 800-53 Rev. 5, selected Low)

This is not a FedRAMP Moderate baseline and not a complete Low overlay. It is the subset an ISSO typically asks a small commercial vendor to narrate.

ControlImplementationInherited?
AC-2 Account managementParticipants: unique seat links, one completer per seat. ALA operators: Cloudflare/Stripe MFA. No participant passwords in this SKUPartial (IdP is the vendor console)
AC-3 Access enforcementFull 50-item score requires a paid credential (402 ENTITLEMENT_REQUIRED without it). Reports other than the public sample 404 by IDALA
AC-17 Remote accessHTTPS only. HSTSCloudflare + ALA
AU-2 / AU-3 Audit eventsCloudflare edge logs; Worker score_attempts table (paid, hourly cap). Not a SIEM export to the agency in this SKUPartial
CA-2 Control assessmentsVendor application security assessment 29 Aug 2026. No 3PAOALA
CM-2 BaselinePages + Workers source under ALA control. Bank freeze documentedALA
CP-9 BackupsCloudflare D1/R2 durability; company 7-day business snapshot. Not an agency contiguous contingency systemCloudflare + ALA
IA-2 IdentificationSeat link + agency-typed Worker ID. No PIVALA (gap vs PIV is disclosed)
IA-5 AuthenticatorBearer invite URL. Agency distributes. Treat as a one-sitting exam linkALA
IR-6 Incident reporting72-hour notice to the named agency contact on confirmed unauthorized access involving that roster. Phone 1-317-751-5444ALA
MP-6 Media sanitizationDeletion within 30 days of written agency request except legal hold. Confirm in writing (DPA)ALA
PL-2 System security planThis pageALA
RA-2 CategorizationLow/Low/Low for ID-only scores. Recategorize if CUI is introduced — then stop using this SKUAgency + ALA
SC-8 Transmission confidentialityTLS 1.3 (walked 29 Aug 2026)Cloudflare
SC-13 CryptographyPlatform TLS; D1/R2 encryption at rest (Cloudflare-managed keys, not customer CMK)Cloudflare
SC-18 Mobile codeFirst-party JS + Cloudflare Insights + optional GA after cookie accept. CSP presentALA
SC-28 Protection at restCloudflare managed storage encryption. No customer-held keysCloudflare
SI-3 / SI-4 Malicious code / monitoringCloudflare WAF at the edge. No agency SOC feed in this SKUCloudflare
SI-10 Information inputCredential format checked; unpaid full score rejected; paid hourly capALA

4. What this SSP-lite does not cover

  • No FedRAMP Moderate control-by-control workbook.
  • No continuous-monitoring package, no POA&M in eMASS, no agency ATO letter.
  • No PIV/CAC, no SAML, no agency IdP.
  • No claim that Cloudflare’s FedRAMP status authorizes Real World Careers.

5. Risk acceptance the ISSO is being asked to make

Use of a Low-impact commercial SaaS, on Cloudflare, for up to 290 exploration profiles identified only by IDs the agency already has, paid as a commercial item under the micro-purchase threshold, with a 72-hour breach notice and a vendor security assessment on file — not authorization of an agency information system, and not permission to use scores for competitive examining.

Hand with: security assessment · DPA · ACR · validation gap · SOW.

Revision 29 August 2026. Reissue if the boundary, subprocessors, or intended use change.