{% extends "security_canvas/base.html" %} {% block title %}ZIG Assessment — NSA Zero Trust{% endblock %} {% block head %} {% endblock %} {% block content %}
ZIG Overview › Assessment

ZIG Gap Assessment

{% if latest %}

Latest Assessment Results

{% for ps in latest.pillar_scores %}
{{ (ps.score * 100)|round(1) }}%
{{ ps.pillar_slug|title }}
{{ ps.maturity_level }}
{% endfor %}
{{ (latest.aggregate.score * 100)|round(1) }}%
Overall ZIG Score
{{ latest.aggregate.maturity_level }}
{% else %}
No assessment results yet.
Click "Run Assessment" to score your ZIG maturity.
{% endif %} {# ── DoD 7-Pillar ZTA Posture (rmf-zt-02) ────────────────────────────── THE TWO NUMBERS ARE RENDERED SEPARATELY AND LABELLED, and are never combined into one figure. "Evidence-backed" is what this deployment can PROVE (a zta_posture_evidence row carrying evidence_data, or a recorded NIST 800-53 control status); "self-attested" is what it has merely TICKED (status='current' with evidence_data NULL). One number cannot say both, and the blended one is the one that reads as reassurance. An UNMEASURED pillar draws a dashed rule, never an empty bar — an empty bar is exactly what a MEASURED 0% looks like, and those two send a reader to opposite places. #}

DoD 7-Pillar ZTA Posture

Two maturity numbers, reported separately. They are never merged.
{% if zta and zta.get('error') %}
ZTA posture unavailable. {{ zta.error }} The panel could not read the store. This is not a clean bill of health.
{% elif not zta or zta.state == 'never_assessed' %}
Never assessed. No ZTA maturity score has ever been persisted for this deployment. Nobody has looked. This is not a clean bill of health.
python tools/devsecops/zta_maturity_scorer.py --project-id <id> --all --human
{% else %}
Evidence-backed (proven)
{% if zta.evidence_backed_score is none %}UNMEASURED{% else %}{{ (zta.evidence_backed_score * 100)|round(1) }}%{% endif %}
{{ zta.evidence_backed_maturity|upper }}
Self-attested (claimed)
{% if zta.self_attested_score is none %}NOTHING CLAIMED{% else %}{{ (zta.self_attested_score * 100)|round(1) }}%{% endif %}
{{ zta.self_attested_maturity|upper }}
{% if zta.state == 'unmeasured' %}
UNMEASURED. An assessment ran and no pillar had an evidence-backed signal behind it. A self-attested figure is a count of ticks, not a measurement — do not read it as posture. This is not a clean bill of health.
{% elif zta.state == 'partial' %}
Partial coverage. {{ zta.measured_pillars|length }} of {{ zta.declared_pillars }} pillars had an evidence-backed signal. The unmeasured ones are excluded from the score above, so it describes only the measured subset.
{% endif %} {% for p in zta.pillars %} {% endfor %}
Pillar Evidence-backed Self-attested
{{ p.label }} {% if p.score is none %} ───── UNMEASURED {% else %} {{ (p.score * 100)|round(1) }}% {{ p.maturity_level }} {% endif %} {% if p.self_attested_score is none %} — {% else %} {{ (p.self_attested_score * 100)|round(1) }}% {% endif %}
{% if zta.assessed_at %}
Last assessed {{ zta.assessed_at }} · read-only, this page runs no assessment.
{% endif %} {% endif %}

What Gets Assessed

⤓ Download ZIG Assessment Report (Markdown)
{% endblock %}