Back to Mattermost

Compliance Frameworks

docs/main/security-guide/compliance-frameworks/index.mdx

11.10.02.4 KB
Original Source

Compliance Frameworks

This section is the canonical home for framework-specific compliance documentation: FedRAMP, DoD IL4/IL5, DISA STIG, FIPS, HIPAA, FINRA, CMMC, and others. Each page below documents Mattermost's authorization posture, the configuration required to align with the framework, and (where applicable) the mapping from framework controls to specific Mattermost features and settings.

:::note Operational vs. framework content Compliance is documented in two places by design:

  • Frameworks (here): authorization status, control mappings, configuration guidance. Target persona: Security Architect / Accreditor and Compliance Officer.
  • Operational machinery (Administration Guide → Comply): step-by-step procedures for running compliance exports, eDiscovery searches, Legal Hold, data retention. Target persona: Administrator and Compliance Officer.

Cross-link both ways when adding new content. :::

Pages

  • FedRAMP Moderate — Authorization status, configuration guidance, and NIST 800-53 control mappings.
  • DoD IL4 / IL5 — Posture against DoD Cloud Computing Security Requirements Guide Impact Levels 4 and 5.
  • DISA STIG — Posture against the Application Security and Development SRG and applicable STIG layers.
  • CMMC Compliance — preserved at parent level pending Phase 2 re-organization.
  • HIPAA Compliance — preserved at parent level pending Phase 2 re-organization.
  • FINRA Compliance — preserved at parent level pending Phase 2 re-organization.

How this section is organized

Each framework page leads with an <AttestationStatus> badge stating Mattermost's current authorization posture (Authorized / In Process / Roadmap / Not Pursued). Pages with "In Process" or "Roadmap" status document the gap honestly — what controls are met today, what's not, and the expected timeline.

For legally citable attestation letters, see the Mattermost Trust Portal (external). The pages in this section describe configuration and control mappings — they do not substitute for the formal attestation artifacts.