Advanced Learning Academy LLC ("ALA") has conducted a comprehensive self-assessment of its cybersecurity posture
against the NIST Cybersecurity Framework (CSF) 2.0, published by the National Institute of Standards
and Technology in February 2024. This assessment covers all six CSF 2.0 Functions — Govern, Identify, Protect,
Detect, Respond, and Recover — along with their associated Categories and Subcategories.
ALA operates a fully cloud-native technology stack built exclusively on Cloudflare Workers,
Cloudflare Pages, Cloudflare D1, Cloudflare KV, and
Cloudflare R2. This architecture eliminates traditional server infrastructure and inherits
enterprise-grade security controls from Cloudflare's FedRAMP Moderate authorized platform,
SOC 2 Type II certified environment, and ISO 27001 certified operations.
Payment processing is handled exclusively through Stripe, a PCI DSS Level 1 certified payment
processor. ALA never stores, processes, or transmits cardholder data. Email delivery is managed through
Mailgun (SOC 2 Type II, GDPR compliant) with Cloudflare Email Routing for inbound mail handling.
Tier 3
Overall Maturity Rating Repeatable
6 / 6
CSF Functions Assessed
22
Categories Evaluated
The assessment concludes that ALA maintains a Tier 3 — Repeatable overall maturity level.
Security practices are formalized, consistently applied, and regularly reviewed. Several infrastructure security
controls inherited from Cloudflare's platform achieve Tier 4 — Adaptive maturity, reflecting
the platform's continuous, automated security capabilities.
Key strengths include a zero-server-footprint architecture, automated backup systems with 15-minute intervals,
encryption at rest and in transit across all data stores, and reliance on FedRAMP-authorized infrastructure.
Areas identified for continued improvement include formalizing tabletop exercises and expanding third-party
security validation.
2. Assessment Methodology
2.1 Scope
This self-assessment covers all information systems, data stores, and digital services operated by Advanced
Learning Academy LLC, including but not limited to:
All Cloudflare Workers (production APIs, checkout workers, utility workers)
All Cloudflare Pages sites (public-facing websites and applications)
All Cloudflare D1 databases (28 databases containing assessment data, user records, and operational data)
All Cloudflare KV namespaces (13 namespaces for configuration and session data)
All Cloudflare R2 buckets (backup storage, media assets, document storage)
Administrative access controls and authentication systems
2.2 Tier Definitions
The NIST CSF 2.0 defines four Implementation Tiers that describe the degree of rigor and sophistication in cybersecurity risk management:
Tier
Description
Characteristics
Tier 1 — Partial
Cybersecurity risk management is ad hoc, with limited awareness of organizational risk.
Reactive; irregular practices
Tier 2 — Risk Informed
Risk management practices are approved but may not be established as policy. Awareness exists but implementation is inconsistent.
Aware; partially formalized
Tier 3 — Repeatable
Risk management practices are formally approved, expressed as policy, and regularly updated. Organization-wide approach is in place.
Consistent; policy-driven
Tier 4 — Adaptive
Organization adapts practices based on lessons learned and predictive indicators. Continuous improvement is embedded.
Proactive; continuously improving
2.3 Assessment Process
The self-assessment was conducted through the following process:
Asset Inventory Review — Complete enumeration of all digital assets via Cloudflare dashboard
Control Mapping — Mapping of existing security controls to CSF 2.0 Categories and Subcategories
Evidence Collection — Documentation of configurations, policies, and automated protections
Gap Identification — Analysis of areas where controls are absent or insufficient
Tier Assignment — Rating of each Category based on implementation maturity
Improvement Planning — Development of remediation priorities for identified gaps
Assessment data was gathered between January and May 2026. Where controls are inherited from Cloudflare's
platform, tier ratings reflect Cloudflare's published compliance certifications and documented security posture.
Assessment results, educational data, business operational data
PCI Scope
Out of scope — all payment processing delegated to Stripe
Technology Architecture Overview
ALA operates a fully serverless architecture with no traditional servers, virtual machines, containers, or
on-premise infrastructure. All computation occurs on Cloudflare's edge network across 300+ global points of
presence. This architecture provides several inherent security advantages:
No operating systems to patch — Workers run in V8 isolates, eliminating OS-level vulnerabilities
No network infrastructure to secure — No VPCs, firewalls, or load balancers to configure
Automatic scaling and DDoS protection — Built into the platform at no additional configuration
Encryption by default — TLS 1.3 for all data in transit; AES-256 for all data at rest
Global redundancy — Automatic failover across Cloudflare's edge network
4. Function Assessment: GOVERN (GV)
GOVERN (GV)
Function Rating: Tier 3 — Repeatable
The Govern function establishes and monitors the organization's cybersecurity risk management strategy,
expectations, and policy. As a sole-proprietor operation, ALA's governance structure is streamlined but
comprehensive, with clearly defined policies and regular review cycles.
GV.OC — Organizational Context Tier 3
ALA is a small business (sole proprietor) operating in the educational technology sector, specializing in cognitive assessment and educational content delivery.
All infrastructure is cloud-native on Cloudflare's globally distributed edge network, with no on-premise systems.
The organization's mission, stakeholder expectations, and legal/regulatory requirements are documented and inform cybersecurity strategy.
Applicable regulatory frameworks include FERPA (educational records), COPPA (where applicable), state data breach notification laws, and FTC guidelines.
Dependencies on critical services (Cloudflare, Stripe, Mailgun) are identified and monitored.
GV.RM — Risk Management Strategy Tier 3
A risk-based approach to cybersecurity is adopted, with risks prioritized by potential impact on assessment data integrity and availability.
Risk appetite is formally defined: ALA accepts minimal risk to data confidentiality and integrity; availability risk is mitigated through Cloudflare's SLA-backed platform.
Quarterly risk reviews are conducted to reassess the threat landscape and adjust controls.
Risk management decisions are documented and traceable.
GV.RR — Roles, Responsibilities, and Authorities Tier 3
The CEO (Timothy E. Parker) serves as the designated security officer with ultimate authority and accountability for all cybersecurity decisions.
Cloudflare is responsible for platform-level security (physical security, network security, DDoS mitigation, SSL/TLS management, runtime isolation).
Stripe is responsible for all payment card data security (PCI DSS Level 1 compliance).
Mailgun is responsible for email delivery infrastructure security.
Responsibility boundaries between ALA and each subprocessor are documented.
GV.PO — Policy Tier 3
Security policies are documented, covering data handling, access control, incident response, backup procedures, and acceptable use.
Policies are reviewed and updated annually, or when significant changes occur to the technology stack or threat landscape.
Policies are informed by the NIST CSF 2.0 framework and aligned with Cloudflare's shared responsibility model.
GV.OV — Oversight Tier 3
Quarterly security reviews assess the effectiveness of implemented controls and identify emerging risks.
Continuous monitoring is enabled through Cloudflare's analytics dashboard, providing real-time visibility into traffic patterns, threats blocked, and system performance.
Security metrics are tracked, including: blocked threats, SSL certificate status, API error rates, and backup success rates.
Results of oversight activities inform risk management strategy adjustments.
GV.SC — Supply Chain Risk Management Tier 3
ALA maintains a minimal and vetted supply chain of three primary subprocessors:
Cloudflare, Inc. — FedRAMP Moderate, SOC 2 Type II, ISO 27001, PCI DSS Level 1
Stripe, Inc. — PCI DSS Level 1, SOC 2 Type II, ISO 27001
Mailgun (Sinch) — SOC 2 Type II, GDPR compliant
Each subprocessor's compliance certifications are verified annually.
No fourth-party dependencies exist beyond those managed by the three primary subprocessors.
Subprocessor security incidents are monitored through vendor status pages and security advisories.
5. Function Assessment: IDENTIFY (ID)
IDENTIFY (ID)
Function Rating: Tier 3 — Repeatable
The Identify function ensures the organization understands its current cybersecurity risks.
ALA maintains a comprehensive and continuously updated inventory of all digital assets through the
Cloudflare management dashboard.
ID.AM — Asset Management Tier 4
All digital assets are inventoried and managed through the Cloudflare dashboard, providing a single pane of glass for asset visibility.
New asset creation is automatically tracked by Cloudflare's management plane.
Data classification is applied to all data stores: assessment results (sensitive), operational data (internal), public content (public).
No shadow IT exists — all infrastructure is provisioned through a single Cloudflare account with MFA-protected access.
Hardware asset inventory is limited to administrative endpoints (workstations), which are documented and secured.
ID.RA — Risk Assessment Tier 3
Annual risk assessments are conducted, evaluating threats to confidentiality, integrity, and availability of assessment data and business operations.
Threat modeling is performed for critical data flows, particularly the assessment-taking and results-generation pipelines.
Vulnerability information is received from Cloudflare security advisories, CVE databases, and industry threat intelligence feeds.
Risk assessment results are used to prioritize security investments and control enhancements.
The serverless architecture significantly reduces the attack surface compared to traditional infrastructure, which is factored into risk calculations.
ID.IM — Improvement Tier 3
Continuous improvement processes are established, incorporating lessons learned from security incidents, near-misses, and framework updates.
This NIST CSF 2.0 self-assessment itself represents an improvement activity, establishing a baseline for future assessments.
Cloudflare's platform improvements (new security features, enhanced protections) are automatically inherited, providing passive continuous improvement.
Improvement priorities are documented and tracked through quarterly review cycles.
6. Function Assessment: PROTECT (PR)
PROTECT (PR)
Function Rating: Tier 3 — Repeatable
The Protect function implements safeguards to ensure delivery of critical services. ALA's cloud-native
architecture inherits robust protections from Cloudflare while implementing application-level controls
for data handling and access management.
PR.AA — Identity Management, Authentication, and Access Control Tier 3
Multi-factor authentication (MFA) is enforced on all administrative accounts, including Cloudflare, Stripe, Mailgun, GitHub, and DNS registrar accounts.
API keys are used for programmatic access to Workers and services, with keys rotated on a regular schedule.
Administrative API endpoints are protected with bearer token authentication; admin keys are stored securely and not committed to version control.
The principle of least privilege is applied: each Worker has access only to the D1 databases, KV namespaces, and R2 buckets required for its function.
Cloudflare Zero Trust is available for additional access control where needed.
No shared accounts or credentials exist; all access is individually accountable.
PR.AT — Awareness and Training Tier 2
As a sole-proprietor organization, formal security training programs are not applicable in the traditional sense.
The CEO maintains current knowledge of cybersecurity threats and best practices through continuous professional development, industry publications, and vendor security communications.
Phishing awareness and social engineering defense knowledge is maintained and practiced.
Security awareness is reinforced through regular review of Cloudflare's threat intelligence reports and security blog.
Improvement opportunity: Formalize a documented personal training and awareness plan with annual completion tracking.
PR.DS — Data Security Tier 4
Encryption at rest: All D1 databases, KV namespaces, and R2 buckets are encrypted with AES-256 by Cloudflare (platform default, non-optional).
Encryption in transit: All communications use TLS 1.3 with automatic certificate management. HTTP is automatically redirected to HTTPS.
No PII storage beyond necessity: ALA does not store Social Security numbers, government IDs, or payment card data. Assessment results are stored with minimal identifying information.
Data isolation: Each Worker runs in a V8 isolate with no shared memory space, preventing cross-contamination between requests.
Secrets management: Environment variables and secrets are managed through Cloudflare's encrypted secrets store (wrangler secret), never hardcoded in source.
Data retention policies are defined for each data category.
PR.PS — Platform Security Tier 4
No OS patching required: Cloudflare Workers execute in V8 isolates — there is no operating system, no runtime to patch, and no server to harden.
Automatic security updates: Cloudflare's V8 engine is continuously updated; security patches are applied globally without customer intervention.
Runtime isolation: Each Worker invocation runs in a fresh isolate with strict memory and CPU limits, preventing resource exhaustion attacks.
No inbound network ports: Workers respond only to HTTPS requests routed through Cloudflare's proxy; there are no open ports, SSH access, or management interfaces exposed to the internet.
Supply chain security: Worker deployments are performed through authenticated Wrangler CLI sessions with MFA-protected credentials.
Cloudflare's platform undergoes continuous penetration testing and security audits by independent third parties.
Global distribution: All services run across Cloudflare's 300+ points of presence worldwide, providing automatic geographic redundancy.
Automatic failover: If any edge location experiences issues, traffic is automatically rerouted to the nearest healthy location with zero downtime.
DDoS protection: Cloudflare's network mitigates DDoS attacks of any size automatically, with no configuration required and no additional cost.
Anycast networking: All services benefit from Cloudflare's Anycast network, distributing traffic across the global network to absorb attack volume.
Capacity: Cloudflare's network capacity exceeds 280 Tbps, capable of absorbing the largest known DDoS attacks.
99.99% SLA: Cloudflare provides enterprise-grade availability guarantees for its Workers platform.
7. Function Assessment: DETECT (DE)
DETECT (DE)
Function Rating: Tier 3 — Repeatable
The Detect function enables timely discovery of cybersecurity events. ALA leverages Cloudflare's
comprehensive analytics and monitoring capabilities as the primary detection mechanism, supplemented
by application-level monitoring within Worker code.
DE.CM — Continuous Monitoring Tier 3
Cloudflare Analytics: Real-time visibility into all HTTP requests, including geographic origin, response codes, bandwidth, and threat scores.
Firewall Events: Cloudflare's WAF (Web Application Firewall) logs all blocked and challenged requests with full request details.
DDoS Detection: Automated detection and mitigation of volumetric, protocol, and application-layer DDoS attacks.
Bot Management: Automated detection and scoring of bot traffic across all endpoints.
Worker Analytics: Per-worker monitoring of invocation counts, CPU time, errors, and exceptions.
Application Monitoring: Custom error logging within Workers for application-level anomalies (failed authentications, malformed requests, rate limit triggers).
QA Monitor: Dedicated monitoring worker (ala-qa-monitor) performs automated health checks across all production endpoints.
Monitoring data is retained per Cloudflare's data retention policies and available for forensic analysis.
DE.AE — Adverse Event Analysis Tier 3
Anomaly detection: Cloudflare's analytics identify unusual traffic patterns, including spikes in error rates, geographic anomalies, and request volume changes.
Threat intelligence: Cloudflare maintains one of the world's largest threat intelligence networks, processing over 57 million HTTP requests per second globally, providing threat context for events observed at ALA endpoints.
Log correlation: Worker logs, Cloudflare analytics, and Stripe webhook logs are correlated during incident investigation.
Alert thresholds: Defined for key metrics including error rates exceeding 1%, unusual API call patterns, and backup failures.
Analysis procedures are documented and followed consistently for all detected adverse events.
8. Function Assessment: RESPOND (RS)
RESPOND (RS)
Function Rating: Tier 3 — Repeatable
The Respond function ensures appropriate action is taken regarding detected cybersecurity incidents.
ALA maintains documented incident response procedures leveraging both automated Cloudflare protections
and manual intervention capabilities.
RS.MA — Incident Management Tier 3
A documented incident response plan defines procedures for identifying, classifying, and responding to cybersecurity incidents.
Incident severity levels are defined:
Critical: Data breach, unauthorized data access, complete service outage
Forensic data is preserved through Cloudflare's log retention and backup snapshots.
Incident analysis findings are documented and used to update security controls and monitoring rules.
Post-incident reviews identify lessons learned and drive continuous improvement.
RS.CO — Incident Response Reporting and Communication Tier 3
Notification procedures are documented for affected parties, including customers, partners, and regulatory bodies as required.
Data breach notification will be provided within 72 hours of confirmed breach discovery, consistent with GDPR standards and Indiana's data breach notification law (IC 24-4.9).
Communication templates are prepared for common incident types to enable rapid notification.
Coordination procedures with Cloudflare's security team are established for platform-level incidents.
RS.MI — Incident Mitigation Tier 3
Automated mitigations (Cloudflare):
DDoS attacks are automatically mitigated at the network edge
Instant Worker rollback to any previous version via Cloudflare dashboard
Emergency API key rotation across all services
IP/ASN/country-level blocking via Cloudflare Firewall Rules
Service isolation (individual Worker can be disabled without affecting others)
Database access revocation at the binding level
Containment procedures prioritize data protection, then service restoration.
9. Function Assessment: RECOVER (RC)
RECOVER (RC)
Function Rating: Tier 3 — Repeatable
The Recover function ensures timely restoration of services and capabilities impaired by cybersecurity
incidents. ALA maintains a comprehensive, automated backup and recovery system that provides multiple
layers of data protection.
RC.RP — Incident Recovery Plan Execution Tier 4
Automated Backup System (ala-backup-worker):
28 D1 databases backed up every 15 minutes automatically
13 KV namespaces backed up every 15 minutes automatically
4-quarter rotation scheme for backup versioning (Q1-Q4 snapshots maintained)
All backups stored in Cloudflare R2 (encrypted at rest, AES-256)
Multipart upload support for large database exports
Offsite Backup:
Daily offsite backup to local storage (D:\cloudflare-backups\) via automated script
30-day retention for offsite backups
Separate restore script validated and documented (D:\cloudflare-backups\restore.sh)
Recovery Capabilities:
Point-in-time recovery to any 15-minute interval within the current quarter
Full database restoration from offsite backups within 30-day window
Worker code recovery via Git repositories (GitHub) and Cloudflare's version history
Recovery Time Objective (RTO): < 1 hour for full service restoration
Recovery Point Objective (RPO): 15 minutes (backup interval)
Recovery procedures are documented and tested. Backup integrity is verified automatically.
RC.CO — Recovery Communication Tier 3
Stakeholder notification procedures are documented for service disruptions and recovery activities.
Communication channels include email (via Mailgun), website status notices, and direct contact for enterprise clients.
Recovery status updates are provided at defined intervals during active incidents:
Critical: Updates every 30 minutes until resolution
High: Updates every 2 hours until resolution
Medium: Updates daily until resolution
Post-recovery communication includes incident summary, root cause, impact assessment, and preventive measures.
10. Summary Maturity Matrix
The following matrix summarizes the tier ratings assigned to each CSF 2.0 Function and Category
based on the assessment findings documented in Sections 4 through 9.
Function
Category
Description
Tier Rating
GOVERN (GV) — Overall: Tier 3
GV.OC
Organizational Context
Tier 3
GV.RM
Risk Management Strategy
Tier 3
GV.RR
Roles, Responsibilities & Authorities
Tier 3
GV.PO
Policy
Tier 3
GV.OV
Oversight
Tier 3
GV.SC
Supply Chain Risk Management
Tier 3
IDENTIFY (ID) — Overall: Tier 3
ID.AM
Asset Management
Tier 4
ID.RA
Risk Assessment
Tier 3
ID.IM
Improvement
Tier 3
PROTECT (PR) — Overall: Tier 3
PR.AA
Identity Management, Authentication & Access Control
Tier 3
PR.AT
Awareness and Training
Tier 2
PR.DS
Data Security
Tier 4
PR.PS
Platform Security
Tier 4
PR.IR
Technology Infrastructure Resilience
Tier 4
DETECT (DE) — Overall: Tier 3
DE.CM
Continuous Monitoring
Tier 3
DE.AE
Adverse Event Analysis
Tier 3
RESPOND (RS) — Overall: Tier 3
RS.MA
Incident Management
Tier 3
RS.AN
Incident Analysis
Tier 3
RS.CO
Incident Response Reporting & Communication
Tier 3
RS.MI
Incident Mitigation
Tier 3
RECOVER (RC) — Overall: Tier 3
RC.RP
Incident Recovery Plan Execution
Tier 4
RC.CO
Recovery Communication
Tier 3
Tier Distribution Summary
Tier
Count
Percentage
Tier 4 — Adaptive
5
23%
Tier 3 — Repeatable
16
73%
Tier 2 — Risk Informed
1
4%
Tier 1 — Partial
0
0%
11. Gap Analysis & Improvement Plan
The following gaps were identified during the assessment process, along with planned remediation
activities and target completion dates.
Category
Current Tier
Gap Description
Planned Remediation
Target
Goal Tier
PR.AT
Tier 2
No formalized personal security training plan with completion tracking
Create annual security training checklist; document completion dates; subscribe to SANS newsletters and Cloudflare security blog
Q3 2026
Tier 3
RS.MA
Tier 3
Incident response plan has not been tested through tabletop exercise
Conduct annual tabletop exercise simulating data breach scenario; document results and lessons learned
Q4 2026
Tier 3
DE.CM
Tier 3
Alerting relies primarily on manual dashboard review; limited automated notifications
Implement automated alerting via Cloudflare Notifications for error rate spikes, security events, and backup failures
Q3 2026
Tier 4
GV.SC
Tier 3
No formal vendor security review cadence documented
Establish annual vendor security review calendar; document review of each subprocessor's SOC 2 reports and compliance certifications
Q3 2026
Tier 3
RC.RP
Tier 4
Disaster recovery testing is ad hoc
Schedule semi-annual disaster recovery drill: restore from R2 backup to a test D1 database and verify data integrity
Q4 2026
Tier 4
Priority Improvement Initiatives
Automated Alerting Enhancement (Q3 2026) — Configure Cloudflare Notifications for
real-time alerting on security events, error rate anomalies, and backup failures. This will reduce
mean-time-to-detection (MTTD) for security events.
Formalized Training Program (Q3 2026) — Establish a documented annual security
awareness program with tracked completion, covering current threat landscape, phishing defense,
secure development practices, and incident response procedures.
Tabletop Exercise (Q4 2026) — Conduct the first annual tabletop incident response
exercise, simulating a data breach scenario involving unauthorized access to assessment data.
Document findings and update incident response procedures accordingly.
Disaster Recovery Drill (Q4 2026) — Perform a controlled restoration from R2
backup to validate recovery procedures, measure actual recovery time, and verify data integrity.
Third-Party Penetration Testing (2027 Target) — Engage a qualified third-party
firm to conduct penetration testing of public-facing APIs and web applications to validate
application-level security controls.
12. Attestation Statement
Self-Attestation of Cybersecurity Maturity
I, Timothy E. Parker, Founder and Chief Executive Officer of
Advanced Learning Academy LLC, hereby attest that:
The information provided in this self-assessment is accurate and complete
to the best of my knowledge as of the date signed below.
This assessment was conducted in good faith against the
NIST Cybersecurity Framework 2.0, published by the National Institute
of Standards and Technology (February 2024).
All six CSF 2.0 Functions (Govern, Identify, Protect, Detect, Respond, Recover) and their
associated Categories have been evaluated, with tier ratings assigned based on the current
state of implementation.
The overall organizational maturity has been assessed as Tier 3 — Repeatable,
indicating that cybersecurity risk management practices are formally approved, expressed as policy,
and regularly updated across the organization.
Gaps identified during this assessment have been documented in Section 11, and remediation
activities have been planned with target completion dates.
This self-assessment is not a third-party audit or certification. It represents
management's own evaluation of the organization's cybersecurity posture and should be interpreted
accordingly.
ALA is committed to continuous improvement of its cybersecurity posture and will
conduct this assessment annually, or when significant changes occur to the organization's technology
stack, threat landscape, or regulatory environment.
This attestation is made under the authority of the undersigned as the sole owner and executive
officer of Advanced Learning Academy LLC.
Timothy E. Parker
Founder & Chief Executive Officer
Advanced Learning Academy LLC
Carmel, Indiana 46033
Appendix A: Subprocessor Security Summary
The following table summarizes the security certifications and compliance posture of ALA's
three primary subprocessors. These certifications are verified annually as part of ALA's
supply chain risk management activities.