CICB compliance and assurance boundary
CICB is a commercial Windows software component that a Mission Owner may include in a larger governance, risk, and compliance program. A visible endpoint banner can support awareness and handling context, but it does not satisfy a control framework or authorize a system by itself.
Current vendor evidence
- CICB 2.9.11.162 dependency evidence covers Qt 6.10.3, OpenSSL 3.0.21, and FFmpeg 7.1.5.
- The assessed installer and principal applications carry valid ARKSOFT INC Authenticode signatures.
- The Standard product assessment records 12 Not a Finding, 7 Open, and 6 Not Reviewed checks.
- The Air-gap product assessment records 22 Not a Finding, 7 Open, and 6 Not Reviewed checks.
- All 286 DISA Application Security and Development STIG V6R4 rules are imported; importing a rule does not complete its Examine, Interview, or Test procedure.
Open product areas
Open or unreviewed areas include unique identity and authorization, runtime secret provisioning, managed PKI and client authentication, FIPS 140-3 approved-mode evidence, continuous database protection, attributable security audit/SIEM handling, installed ACLs, failure-state marking, and independent testing.
Policy context
Customers may evaluate CICB alongside 32 CFR Part 2002, the NARA CUI Registry, NIST SP 800-171, DoDI 5200.48 where applicable, NIST SP 800-53, customer security classification guides, contracts, and organization-specific policy. These sources do not certify a particular banner product.
Evidence, not authorization
This vendor component evidence is not an ATO, official STIG approval, FIPS certificate, NIAP or NIAPC validation, Common Criteria certification, CMMC certification, or DoD Impact Level authorization. The customer must assess CICB within the complete system boundary.
