SSP-RWC-FED-2026-08-29 · FIPS 199 Low · not an ATO
System Security Plan (lite).
Short control narrative for Federal Fit Scale ($14,500 / 290 seats). Architecture detail lives on the security statement. Data roles live on the DPA. FedRAMP is not authorized. The buying agency remains the authorizing official for its own use.
1. System identification
| Field | Value |
|---|---|
| Information system | Real World Careers Federal Fit (commercial SaaS) |
| System owner | Advanced Learning Academy LLC · UEI Z272LH7MCDT2 · CAGE 1A8H4 |
| Location | 1950 E Greyhound Pass, Carmel, IN 46033 · cloud: Cloudflare (United States) |
| Public origin | https://realworldcareers.com |
| FIPS 199 (this SKU) | Confidentiality Low · Integrity Low · Availability Low — if the agency stores only Employer Worker IDs and scores, not SSN, not classified, not CUI |
| CUI | Not intended. If the agency designates the file as CUI, this SKU is the wrong system |
| FedRAMP | Not authorized. Cloudflare’s platform has its own authorizations; they do not confer an ATO on this customer SaaS |
| GSA Schedule | None |
| POC | Timothy E. Parker, CEO · team@advancedlearning.academy · 1-317-751-5444 |
2. Authorization boundary
- Agency admin types Employer Worker IDs (not names, not SSN) into numbered seats.
- Participant opens a unique HTTPS invite, answers 50 items in the browser.
- Cloudflare Worker scores the session. D1 stores credential, scores, completion metadata.
- Agency retrieves HTML reports and CSV over HTTPS. Agency owns the export.
- Stripe processes the card (or the agency invoices Net 30 ACH). Mailgun sends transactional mail if ALA is asked to mail invites — default is the agency sends access in its own mail.
No on-prem agent. No mobile-app binary. No PIV/SSO in this SKU. Subprocessors: Cloudflare (compute/storage/DNS/WAF), Stripe (payments), Mailgun/Sinch (email). Detail: security.html.
3. Control implementation (NIST SP 800-53 Rev. 5, selected Low)
This is not a FedRAMP Moderate baseline and not a complete Low overlay. It is the subset an ISSO typically asks a small commercial vendor to narrate.
| Control | Implementation | Inherited? |
|---|---|---|
| AC-2 Account management | Participants: unique seat links, one completer per seat. ALA operators: Cloudflare/Stripe MFA. No participant passwords in this SKU | Partial (IdP is the vendor console) |
| AC-3 Access enforcement | Full 50-item score requires a paid credential (402 ENTITLEMENT_REQUIRED without it). Reports other than the public sample 404 by ID | ALA |
| AC-17 Remote access | HTTPS only. HSTS | Cloudflare + ALA |
| AU-2 / AU-3 Audit events | Cloudflare edge logs; Worker score_attempts table (paid, hourly cap). Not a SIEM export to the agency in this SKU | Partial |
| CA-2 Control assessments | Vendor application security assessment 29 Aug 2026. No 3PAO | ALA |
| CM-2 Baseline | Pages + Workers source under ALA control. Bank freeze documented | ALA |
| CP-9 Backups | Cloudflare D1/R2 durability; company 7-day business snapshot. Not an agency contiguous contingency system | Cloudflare + ALA |
| IA-2 Identification | Seat link + agency-typed Worker ID. No PIV | ALA (gap vs PIV is disclosed) |
| IA-5 Authenticator | Bearer invite URL. Agency distributes. Treat as a one-sitting exam link | ALA |
| IR-6 Incident reporting | 72-hour notice to the named agency contact on confirmed unauthorized access involving that roster. Phone 1-317-751-5444 | ALA |
| MP-6 Media sanitization | Deletion within 30 days of written agency request except legal hold. Confirm in writing (DPA) | ALA |
| PL-2 System security plan | This page | ALA |
| RA-2 Categorization | Low/Low/Low for ID-only scores. Recategorize if CUI is introduced — then stop using this SKU | Agency + ALA |
| SC-8 Transmission confidentiality | TLS 1.3 (walked 29 Aug 2026) | Cloudflare |
| SC-13 Cryptography | Platform TLS; D1/R2 encryption at rest (Cloudflare-managed keys, not customer CMK) | Cloudflare |
| SC-18 Mobile code | First-party JS + Cloudflare Insights + optional GA after cookie accept. CSP present | ALA |
| SC-28 Protection at rest | Cloudflare managed storage encryption. No customer-held keys | Cloudflare |
| SI-3 / SI-4 Malicious code / monitoring | Cloudflare WAF at the edge. No agency SOC feed in this SKU | Cloudflare |
| SI-10 Information input | Credential format checked; unpaid full score rejected; paid hourly cap | ALA |
4. What this SSP-lite does not cover
- No FedRAMP Moderate control-by-control workbook.
- No continuous-monitoring package, no POA&M in eMASS, no agency ATO letter.
- No PIV/CAC, no SAML, no agency IdP.
- No claim that Cloudflare’s FedRAMP status authorizes Real World Careers.
5. Risk acceptance the ISSO is being asked to make
Use of a Low-impact commercial SaaS, on Cloudflare, for up to 290 exploration profiles identified only by IDs the agency already has, paid as a commercial item under the micro-purchase threshold, with a 72-hour breach notice and a vendor security assessment on file — not authorization of an agency information system, and not permission to use scores for competitive examining.
Hand with: security assessment · DPA · ACR · validation gap · SOW.
Revision 29 August 2026. Reissue if the boundary, subprocessors, or intended use change.