FinancialSecurityPlan.md
April 28, 2026 ยท View on GitHub
๐ฐ CIA Compliance Manager โ Financial & Security Plan
๐ Infrastructure Cost Analysis & Security Investment
๐ Secure Development Policy ยท Classification Framework
๐ Document Owner: CEO | ๐ Version: 1.2 | ๐
Last Updated: 2026-04-28 (UTC)
๐ Review Cycle: Semi-Annual | โฐ Next Review: 2026-10-21
๐ Purpose
This document outlines the financial and security implementation plan for the CIA Compliance Manager platform. For architectural context, see the Architecture Documentation and End-of-Life Strategy.
๐ต v1.1.59 Cost Summary โ AWS + GitHub Pages DR + npm Distribution
The current v1.1.59 delivery is a static React 19 SPA distributed across three channels:
- Primary: AWS CloudFront + S3 (production at
ciacompliancemanager.com), deployed by.github/workflows/deploy-s3.ymlusing IAM OIDC and CloudFormation stackciacompliancemanager-frontend - DR: GitHub Pages (fallback hosting, deployed by
release.yml) - Library: npm registry (
cia-compliance-managerpackage), published by thepublish-npmjob withnpm publish --provenance(Sigstore-signed)
Cash Flow Overview
| Time Frame | Monthly (USD) | Annual (USD) |
|---|---|---|
| AWS Infrastructure (CloudFront + S3 + Route53) | ~$2โ5 | ~$24โ60 |
| Domain Registration | $1 | $12 |
| Security Tooling | $0 | $0 (free OSS tiers) |
| Development CI/CD | $0 | $0 (GitHub Actions public repo) |
| npm Publishing | $0 | $0 (public package) |
| Grand Total (typical) | ~$3โ6 | ~$36โ72 |
Note: Actual AWS costs scale with traffic; the static SPA incurs minimal S3 storage and CloudFront egress charges. Dev-tier free quotas cover typical usage. Figures assume small-to-moderate traffic; AWS CloudFront free tier further reduces cost for the first 1 TB/month.
๐๏ธ Infrastructure Cost Breakdown (v1.1.59)
| Component | Service | Monthly (USD) | Annual (USD) | Notes |
|---|---|---|---|---|
| Primary Hosting | AWS S3 (ciacompliancemanager-frontend-us-east-1-โฆ) | $0.50โ1.00 | $6โ12 | Static assets, versioned, encrypted at rest |
| Primary CDN | AWS CloudFront | $1.00โ3.00 | $12โ36 | Global edge caching, HTTPS, security headers |
| DNS | AWS Route 53 | $0.50 | $6 | Hosted zone + DNS queries |
| Domain | Registrar (ciacompliancemanager.com) | $1.00 | $12 | Annual registration averaged |
| IaC | AWS CloudFormation | $0.00 | $0.00 | Included; stack ciacompliancemanager-frontend |
| IAM OIDC | AWS IAM (GithubWorkFlowRole) | $0.00 | $0.00 | No long-lived credentials |
| DR Hosting | GitHub Pages | $0.00 | $0.00 | Free for public repos (DR channel) |
| Library Distribution | npm Registry | $0.00 | $0.00 | Free public package |
| CI/CD | GitHub Actions | $0.00 | $0.00 | Free for public repos |
| Code Scanning | GitHub Advanced Security (CodeQL) | $0.00 | $0.00 | Free for public repos |
| Dependency Scanning | Dependabot | $0.00 | $0.00 | Free for all repos |
| SAST | SonarCloud | $0.00 | $0.00 | Free for open source |
| SBOM + Attestation | GitHub SBOM + SLSA Level 3 | $0.00 | $0.00 | Free for public repos |
| DAST | OWASP ZAP (GitHub Action) | $0.00 | $0.00 | Free OSS scanner |
| Performance Audit | Google Lighthouse CI | $0.00 | $0.00 | Free OSS |
| Supply Chain Score | OpenSSF Scorecard | $0.00 | $0.00 | Free assessment |
| Total | ~$3โ6 | ~$36โ72 |
๐ Security Investment Analysis
Current Security Services (v1.1.59 โ All Free Tier)
| Security Service | Provider | Annual Cost | ISMS Policy Alignment |
|---|---|---|---|
| SAST Scanning | SonarCloud + CodeQL | $0.00 | Secure Development Policy |
| Dependency Scanning | Dependabot + npm audit | $0.00 | Vulnerability Management |
| Secret Scanning | GitHub Secret Scanning + push protection | $0.00 | Cryptography Policy |
| DAST | OWASP ZAP (manual dispatch) | $0.00 | Secure Development Policy |
| Supply Chain | SLSA Level 3 attestation + OpenSSF Scorecard | $0.00 | Open Source Policy |
| CI Runner Hardening | step-security/harden-runner | $0.00 | Network Security Policy |
| License Compliance | FOSSA | $0.00 | Open Source Policy |
| E2E Testing | Cypress 15.14.0 (OSS) | $0.00 | Secure Development Policy |
| Unit/Component Testing | Vitest 4.1.4 (OSS) | $0.00 | Secure Development Policy |
| Dead-code Detection | Knip 6.5.0 (OSS) | $0.00 | Secure Development Policy |
| Package Provenance | npm --provenance (Sigstore) | $0.00 | Open Source Policy |
| Total Security | $0.00 |
Security ROI Metrics
| Metric | Value | Source |
|---|---|---|
| Total Security Investment | $0/year (tooling) + ~$36โ72/year (AWS infra) | Free OSS tooling + minimal AWS hosting |
| Vulnerability Detection Rate | >95% | Automated CodeQL + Dependabot + SonarCloud + ZAP |
| Mean Time to Detect (MTTD) | <24 hours | Automated CI/CD scanning on every PR + weekly schedule |
| Line Coverage | โฅ80% (enforced) | Vitest thresholds in vite.config.ts |
| Supply Chain Score | Live (see OpenSSF Scorecard badge) | scorecards.yml |
| SLSA Build Level | Level 3 | release.yml attestations |
๐ฐ Future Cost Projection โ v2.0 AWS Serverless
The planned evolution to a full-stack AWS serverless platform will introduce infrastructure costs. See Future Architecture for details.
Projected Monthly Costs (v2.0)
| Component | AWS Service | Monthly (USD) | Annual (USD) |
|---|---|---|---|
| Compute | Lambda | $5.00 | $60.00 |
| API | API Gateway | $3.50 | $42.00 |
| Database | DynamoDB (on-demand) | $10.00 | $120.00 |
| Authentication | Cognito | $0.00 | $0.00 |
| Storage | S3 | $1.00 | $12.00 |
| CDN | CloudFront | $5.00 | $60.00 |
| DNS | Route 53 | $0.50 | $6.00 |
| Security - WAF | AWS WAF | $10.00 | $120.00 |
| Security - GuardDuty | GuardDuty | $15.00 | $180.00 |
| Security - Security Hub | Security Hub | $10.00 | $120.00 |
| Security - Inspector | Inspector | $5.00 | $60.00 |
| Monitoring | CloudWatch | $5.00 | $60.00 |
| Encryption | KMS | $3.00 | $36.00 |
| Audit | CloudTrail | $2.00 | $24.00 |
| Total | $75.00 | $900.00 |
Future Security Investment by ISMS Policy
| ๐ก๏ธ ISMS Policy | ๐ฐ Annual Investment | ๐ง AWS Services | ๐ Business Value |
|---|---|---|---|
| Incident Response Plan | $300.00 | GuardDuty, Security Hub | Real-time threat detection |
| Vulnerability Management | $60.00 | Inspector | Continuous vulnerability scanning |
| Cryptography Policy | $36.00 | KMS | Encryption key management |
| Network Security Policy | $120.00 | WAF | Application-layer protection |
| Information Security Policy | $84.00 | CloudTrail, CloudWatch | Audit logging and monitoring |
| Total Security Investment | $600.00 |
๐ Related Documents
| Icon | Document | Relationship |
|---|---|---|
| ๐๏ธ | Architecture | System architecture overview |
| ๐ก๏ธ | Security Architecture | Security model details |
| ๐ฏ | Threat Model | Risk-driven security justification |
| ๐ฎ | Future Architecture | v2.0 evolution roadmap |
| ๐ | End-of-Life Strategy | Technology lifecycle management |
| ๐ | BCPPlan | Business continuity planning |
| ๐ | README | Project overview |
๐ Document Control
Approved by: James Pether Sรถrling, CEO, Hack23 AB
Distribution: Public (GitHub Repository)
Classification: