Before you begin
- Create/select a program for the relevant profile and confirm the Active client and Active program.
- Obtain the expected tenant, asset or builder identity independently of the supplied evidence file.
- These workflows inspect files locally. They do not connect to a tenant, execute DISA checks or automatically approve requirements.
1. Inspect SCuBA results
- Select a CISA SCuBA — Microsoft 365 or CISA SCuBA — Google Workspace program. Open Run Assessment → Inspect external evidence.
- Enter Expected tenant ID using the identity confirmed by the tenant owner. Do not merely copy an unexpected identity from the submitted file.
- For Result / provenance file, choose the ScubaResults JSON exported by the supported tool: ScubaGear 1.8.0 or ScubaGoggles 1.0.0/1.0.1. A screenshot or arbitrary JSON export is not this format.
- Click Inspect evidence. Review Rule / policy, Source result, Review state and Evidence / details. Missing policies remain missing; overrides and annotations require human review.
- If the tool or policy version is rejected, retain the message and obtain a compatible export. Do not edit the version identifier solely to force acceptance.
- Click Save evidence and workpapers, then Open saved report. Review the saved report before attaching it through Evidence. Use Compare previous result only with a compatible prior retained result for the same assessment context.
Check before continuingA local inspection report and workpapers are saved. The relevant reviewed files must still be explicitly uploaded/linked to the assessment.
2. Inspect DISA assessment evidence
- Select a DISA STIG / SRG assessments program and open Run Assessment → Inspect external evidence.
- Enter Expected asset hostname / FQDN. Select an official XCCDF 1.2 Benchmark under Official XCCDF benchmark and a CKL XML or single XCCDF TestResult under Result / provenance file.
- Enter the exact Profile ID when the result uses a profile. Leave it empty only for an unprofiled result. Independently confirm the benchmark release and target.
- Click Inspect evidence. Read missing rules, manual checks, inherited/tailored scope and exceptions. The importer displays check/fix text; it never executes those instructions.
- Use Save evidence and workpapers and Open saved report. Attach the reviewed output to the appropriate requirements. CKLB and generic SCC execution are not supported by this importer.
Check before continuingThe report identifies the supplied benchmark and target, and any missing or review-required checks remain explicit.
3. Inspect SLSA provenance
- Select a SLSA program and open Run Assessment → Inspect external evidence.
- Choose the in-toto Statement v1 / SLSA provenance v1 file under Result / provenance file. Choose the actual deliverable under Artifact to verify.
- Enter Expected artifact subject name exactly as independently expected for that artifact and enter Expected trusted builder ID.
- If performing the supported signature check, select an independently trusted RSA PEM public key under Trusted public key (optional, PEM RSA-PSS). This workflow supports DSSE RSA-PSS SHA-256; it does not provide general Sigstore/transparency-log verification.
- Click Inspect evidence. Review the subject identity, builder identity, artifact SHA-256 and signature status. An unsigned result remains unverified.
- Save the evidence/workpapers and open the report. A matching digest or supported signature does not by itself award a SLSA level; record your independent review before linking it.
Check before continuingThe saved result states which artifact, builder and signature checks actually succeeded or remain unverified.
4. Rate C2M2 practices
- Select a C2M2 program. Open Run Assessment → Rate C2M2 practices.
- Enter Business function / boundary and Reviewer. Confirm that the scope matches the program rather than automatically applying one rating across the whole organization.
- For each practice, read its Action / evidence needed. Record the supported rating, owner and evidence/rationale. Keep practices Not assessed when the evidence is missing.
- Set the intended domain target MIL values in the worksheet. Click Calculate domain maturity and inspect each domain’s result. MILs are cumulative; unassessed lower-level practices remain gaps.
- Click Save worksheet to retain your work and Export maturity report to create the review output. Use Load worksheet to resume the compatible client/program worksheet later.
Check before continuingA saved worksheet and report document evidence-backed ratings. The self-evaluation does not automatically change program approval decisions.
If something goes wrong
Inspect external evidence does not appear
Confirm that the active program is SCuBA, DISA or SLSA. C2M2 uses Rate C2M2 practices instead; other profiles use their own workspaces.
Save/Open saved report is unavailable
Run a successful inspection first and then save it. Changing an input invalidates the prior inspection; inspect again.
A comparison is rejected
Check that the two records belong to the same client, program and supported identity/baseline. Do not compare unrelated targets just because their filenames look similar.