<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Federal Compliance on DefectDojo Documentation</title><link>https://docs.defectdojo.com/federal_compliance/</link><description>Recent content in Federal Compliance on DefectDojo Documentation</description><generator>Hugo</generator><language>en-US</language><copyright>Copyright (c) 2020-2025 DefectDojo, Inc.</copyright><atom:link href="https://docs.defectdojo.com/federal_compliance/index.xml" rel="self" type="application/rss+xml"/><item><title>Compliance Profile</title><link>https://docs.defectdojo.com/federal_compliance/compliance_profile/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/federal_compliance/compliance_profile/</guid><description>&lt;p&gt;The Compliance Profile enrolls an Asset as a system and holds the facts that appear on every
deliverable it produces. Open the Asset that represents your system boundary, go to the
&lt;strong&gt;Compliance&lt;/strong&gt; tab, then &lt;strong&gt;Profile&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>The POA&amp;M Ledger</title><link>https://docs.defectdojo.com/federal_compliance/poam_ledger/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/federal_compliance/poam_ledger/</guid><description>&lt;p&gt;POA&amp;amp;M items are created and updated automatically from findings. The sync runs shortly after
imports and finding changes, and a nightly sweep catches anything that slipped through. You can
also add items by hand, for weaknesses that no scanner reports.&lt;/p&gt;</description></item><item><title>ConMon Snapshots</title><link>https://docs.defectdojo.com/federal_compliance/conmon_snapshots/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/federal_compliance/conmon_snapshots/</guid><description>&lt;p&gt;On the &lt;strong&gt;Snapshots&lt;/strong&gt; tab, &lt;strong&gt;Generate Snapshot&lt;/strong&gt; produces the deliverables for a reporting period.
A snapshot &lt;strong&gt;freezes the ledger&lt;/strong&gt; as of that moment: later edits never change a deliverable you
have already generated.&lt;/p&gt;</description></item><item><title>Remediation Deadlines</title><link>https://docs.defectdojo.com/federal_compliance/remediation_slas/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/federal_compliance/remediation_slas/</guid><description>&lt;p&gt;Two ready-made SLA configurations ship with the feature. Assign either to your products from SLA
configuration settings, or copy one and adjust it.&lt;/p&gt;</description></item><item><title>CMMC Level 2 Assessments</title><link>https://docs.defectdojo.com/federal_compliance/cmmc_assessments/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/federal_compliance/cmmc_assessments/</guid><description>&lt;p&gt;The Compliance tab can score a CMMC Level 2 self-assessment against NIST 800-171 Rev 2, using the
DoD Assessment Methodology point weights.&lt;/p&gt;</description></item><item><title>Control Coverage</title><link>https://docs.defectdojo.com/federal_compliance/control_coverage/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/federal_compliance/control_coverage/</guid><description>&lt;p&gt;The control coverage view answers a simple question: which 800-53 controls do my scanners actually
test, and where are the open weaknesses per control?&lt;/p&gt;</description></item></channel></rss>