Skip to content

Evidence request lists

FedRAMP High

Evidence request list. 410 controls, 410 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

AC - Access Control

AC-1
Policy and Procedures

Develop and disseminate access control policy and procedures; review at least annually (FedRAMP parameter); update following defined events.

Artefacts an auditor will ask for
  • Control implementation statement for AC-1 citing the system mission and inheritance from common controls
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
Where this commonly fails
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
AC-10
Concurrent Session Control

Limit concurrent sessions per account to FedRAMP-defined number (3 for privileged, 2 for non-privileged).

Artefacts an auditor will ask for
  • Session limit config
Where this commonly fails
  • Unlimited concurrent sessions
AC-11
Device Lock

Prevent further access by initiating device lock after 15 minutes inactivity (FedRAMP) or upon user request.

Artefacts an auditor will ask for
  • Control implementation statement for AC-11 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-11(1)
Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image

Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image

Artefacts an auditor will ask for
  • Lock screen image configuration
  • Screenshots showing pattern-hiding
  • MDM payload
Where this commonly fails
  • Lock shows live data
  • Configuration drift
  • No screenshot evidence
AC-12
Session Termination

Automatically terminate user session after FedRAMP-defined conditions (idle timeout, trigger events).

Artefacts an auditor will ask for
  • Control implementation statement for AC-12 citing the system mission and inheritance from common controls
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-14
Permitted Actions Without Identification or Authentication

Identify and document actions allowed without identification or authentication.

Artefacts an auditor will ask for
  • Control implementation statement for AC-14 citing the system mission and inheritance from common controls
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-17
Remote Access

Establish usage restrictions, configuration requirements, and authorize remote access prior to allowing.

Artefacts an auditor will ask for
  • Control implementation statement for AC-17 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
AC-17(1)
Monitoring and Control

Employ automated mechanisms to monitor and control remote access.

Artefacts an auditor will ask for
  • VPN logs
  • Remote session monitoring
Where this commonly fails
  • No remote session logging
AC-17(2)
Protection of Confidentiality and Integrity Using Encryption

Implement cryptographic mechanisms to protect remote access sessions; FIPS-validated.

Artefacts an auditor will ask for
  • FIPS 140 module list
  • TLS config
Where this commonly fails
  • Non-FIPS ciphers enabled
AC-17(3)
Managed Access Control Points

Route remote accesses through FedRAMP-defined number of managed network access control points.

Artefacts an auditor will ask for
  • Network ingress diagram
  • TIC compliance
Where this commonly fails
  • Split tunneling allowed
AC-17(4)
Privileged Commands and Access

Authorize execution of privileged commands and access to security-relevant information via remote access only for defined needs.

Artefacts an auditor will ask for
  • Bastion logs
  • Approved command list
Where this commonly fails
  • No bastion enforcement
AC-18
Wireless Access

Establish configuration requirements, usage restrictions, authorize wireless access.

Artefacts an auditor will ask for
  • Control implementation statement for AC-18 citing the system mission and inheritance from common controls
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
AC-18(1)
Authentication and Encryption

Protect wireless access using authentication and encryption (WPA2/3 Enterprise minimum).

Artefacts an auditor will ask for
  • WPA3 config
  • RADIUS records
Where this commonly fails
  • PSK in use
AC-18(3)
Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment

Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment

Artefacts an auditor will ask for
  • MDM policy
Where this commonly fails
  • Bluetooth/Wi-Fi enabled by default
AC-18(4)
Restrict Configurations by Users

Identify users authorized to independently configure wireless; restrict others.

Artefacts an auditor will ask for
  • MDM lockdown
Where this commonly fails
  • Users add networks freely
AC-18(5)
Antennas and Transmission Power Levels

Select antenna and transmission power to reduce signal leakage outside boundary.

Artefacts an auditor will ask for
  • Site survey
  • RF heatmap
Where this commonly fails
  • No RF leakage assessment
AC-19
Access Control for Mobile Devices

Establish configuration requirements and usage restrictions for mobile devices.

Artefacts an auditor will ask for
  • Control implementation statement for AC-19 citing the system mission and inheritance from common controls
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
AC-19(5)
Full Device or Container-Based Encryption

Employ full device or container-based encryption on mobile devices.

Artefacts an auditor will ask for
  • Encryption attestation
Where this commonly fails
  • Personal containers unencrypted
AC-2
Account Management

Manage accounts; review at least monthly for privileged, every six months for non-privileged (FedRAMP); notify within FedRAMP-defined timeframes on changes.

Artefacts an auditor will ask for
  • Control implementation statement for AC-2 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
AC-2(1)
Automated System Account Management

Support account management via automated mechanisms; required at HIGH baseline.

Artefacts an auditor will ask for
  • IDP configuration
  • Workflow automation evidence
  • SCIM provisioning logs
Where this commonly fails
  • Manual ticket-only provisioning
  • No automated deprovisioning
AC-2(11)
Usage Conditions

Enforce circumstances and usage conditions on account use (time of day, location, etc.).

Artefacts an auditor will ask for
  • Conditional access policies
  • Geo-fencing rules
Where this commonly fails
  • No usage condition enforcement
AC-2(12)
Account Monitoring for Atypical Usage

Monitor accounts for atypical use; report anomalies to defined personnel.

Artefacts an auditor will ask for
  • UEBA reports
  • Anomaly alerts
Where this commonly fails
  • No behavior baseline
AC-2(13)
Disable Accounts for High-Risk Individuals

Disable accounts of users posing significant risk within FedRAMP-defined timeframe (1 hour).

Artefacts an auditor will ask for
  • Insider threat workflow
  • 1-hour disable evidence
Where this commonly fails
  • No coordination with HR/legal
AC-2(2)
Automated Temporary and Emergency Account Management

Automatically disable temporary and emergency accounts within FedRAMP-defined timeframe (no longer than 24 hours).

Artefacts an auditor will ask for
  • Temp account expiry logs
  • Automation script
  • JIT access records
Where this commonly fails
  • No automated expiry
  • Emergency accounts persist
AC-2(3)
Disable Accounts

Disable accounts within FedRAMP-defined timeframe when no longer required, terminated, or inactive (35 days inactive).

Artefacts an auditor will ask for
  • Inactivity disable logs
  • HR-IAM integration
  • 35-day report
Where this commonly fails
  • Inactive accounts active over 35 days
AC-2(4)
Automated Audit Actions

Automatically audit account creation, modification, enabling, disabling, removal; notify defined personnel.

Artefacts an auditor will ask for
  • Account change audit logs
  • Alerting rules
Where this commonly fails
  • No alerts on account changes
AC-2(5)
Inactivity Logout

Require users to log out when inactivity exceeds FedRAMP-defined period (15 minutes for non-mobile, 30 for mobile).

Artefacts an auditor will ask for
  • Session timeout config
  • Policy baseline
Where this commonly fails
  • Timeout over 15 minutes
AC-2(7)
Privileged User Accounts

Establish and administer privileged accounts per role-based scheme; monitor role assignments; revoke when no longer needed.

Artefacts an auditor will ask for
  • Privileged role catalog
  • PAM logs
  • Revocation records
Where this commonly fails
  • Standing admin access
  • No PAM deployment
AC-2(9)
Restrictions on Use of Shared and Group Accounts

Only permit shared/group accounts when meeting FedRAMP-defined conditions; document and approve.

Artefacts an auditor will ask for
  • Shared account inventory
  • Approval records
Where this commonly fails
  • Shared accounts undocumented
AC-20
Use of External Systems

Establish terms and conditions for use of external systems; prohibit unless authorized.

Artefacts an auditor will ask for
  • Control implementation statement for AC-20 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-20(1)
Limits on Authorized Use

Permit use of external systems only after verifying security/privacy controls or approved connection agreement.

Artefacts an auditor will ask for
  • Interconnection agreements
  • Vendor assessments
Where this commonly fails
  • Missing ISA
AC-20(2)
Portable Storage Devices Restricted Use

Restrict use of organization-controlled portable storage on external systems.

Artefacts an auditor will ask for
  • USB control policy
  • DLP rules
Where this commonly fails
  • USB unrestricted
AC-21
Information Sharing

Enable authorized users to determine whether access authorizations match sharing restrictions.

Artefacts an auditor will ask for
  • Sharing policy
  • Classification labels
Where this commonly fails
  • No sharing review process
AC-22
Publicly Accessible Content

Designate users authorized to post; train them; review content quarterly for nonpublic information.

Artefacts an auditor will ask for
  • Control implementation statement for AC-22 citing the system mission and inheritance from common controls
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
AC-3
Access Enforcement

Enforce approved authorizations for logical access in accordance with policy.

Artefacts an auditor will ask for
  • Control implementation statement for AC-3 citing the system mission and inheritance from common controls
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
AC-4
Information Flow Enforcement

Enforce approved information flow control policies between connected systems and within the system.

Artefacts an auditor will ask for
  • Control implementation statement for AC-4 citing the system mission and inheritance from common controls
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-4(21)
Physical or Logical Separation of Information Flows

Separate information flows logically or physically using FedRAMP-defined mechanisms.

Artefacts an auditor will ask for
  • VLAN/VRF design
  • Tenant isolation evidence
Where this commonly fails
  • Shared broadcast domain
AC-4(4)
Flow Control of Encrypted Information

Prevent encrypted information from bypassing flow control mechanisms; required at HIGH.

Artefacts an auditor will ask for
  • TLS inspection config
  • SSL break-and-inspect policy
Where this commonly fails
  • Encrypted bypass paths
AC-5
Separation of Duties

Identify and document duties requiring separation; define access authorizations to support.

Artefacts an auditor will ask for
  • Control implementation statement for AC-5 citing the system mission and inheritance from common controls
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
AC-6
Least Privilege

Employ least privilege; allow only authorized access necessary to accomplish assigned tasks.

Artefacts an auditor will ask for
  • Control implementation statement for AC-6 citing the system mission and inheritance from common controls
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
AC-6(1)
Authorize Access to Security Functions

Authorize access for FedRAMP-defined personnel to security functions and security-relevant information.

Artefacts an auditor will ask for
  • Security admin role list
  • Approval records
Where this commonly fails
  • Undocumented sec-admin access
AC-6(10)
Prohibit Non-Privileged Users from Executing Privileged Functions

Prevent non-privileged users from executing privileged functions.

Artefacts an auditor will ask for
  • LPE prevention controls
  • EDR config
Where this commonly fails
  • Setuid binaries unaudited
AC-6(2)
Non-Privileged Access for Nonsecurity Functions

Require privileged users to use non-privileged accounts for nonsecurity functions.

Artefacts an auditor will ask for
  • Dual-account policy
  • Browse-as-user evidence
Where this commonly fails
  • Admins browse with admin
AC-6(3)
Network Access to Privileged Commands

Authorize network access to privileged commands only for FedRAMP-defined needs; document rationale.

Artefacts an auditor will ask for
  • Bastion/jump-host config
  • Approved command list
Where this commonly fails
  • Direct admin from internet
AC-6(5)
Privileged Accounts

Restrict privileged accounts to FedRAMP-defined personnel or roles.

Artefacts an auditor will ask for
  • Privileged role list
  • Quarterly review
Where this commonly fails
  • No periodic review
AC-6(7)
Review of User Privileges

Review privileges at least quarterly (FedRAMP) and reassign or remove as needed.

Artefacts an auditor will ask for
  • Quarterly privilege review
  • Remediation tickets
Where this commonly fails
  • Annual-only review
AC-6(8)
Privilege Levels for Code Execution

Prevent specified software from executing at higher privilege levels than necessary.

Artefacts an auditor will ask for
  • App allowlist
  • Privilege escalation logs
Where this commonly fails
  • Tools run as SYSTEM/root
AC-6(9)
Log Use of Privileged Functions

Log execution of privileged functions.

Artefacts an auditor will ask for
  • Sudo logs
  • PAM session recording
Where this commonly fails
  • No PAM session logs
AC-7
Unsuccessful Logon Attempts

Enforce limit of 3 consecutive invalid logon attempts within 15 minutes (FedRAMP); lock for 30 min or until released.

Artefacts an auditor will ask for
  • Control implementation statement for AC-7 citing the system mission and inheritance from common controls
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-8
System Use Notification

Display approved system use notification/banner before granting access; FedRAMP requires specific language.

Artefacts an auditor will ask for
  • Login banner screenshot
  • Banner text
Where this commonly fails
  • Missing FedRAMP banner language

AT - Awareness and Training

AT-1
Policy and Procedures

Develop, disseminate, and review awareness and training policy and procedures at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for AT-1 citing the system mission and inheritance from common controls
  • Insider threat awareness briefing materials
  • Training records retained in the learning management system
  • Attestation records signed at onboarding and annually
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
Where this commonly fails
  • Contractors and third parties not enrolled in mandatory training
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
  • Training content not reviewed annually for current threat trends
AT-2
Literacy Training and Awareness

Provide security awareness training within FedRAMP-defined timeframe of onboarding, on system change, and at least annually thereafter.

Artefacts an auditor will ask for
  • Control implementation statement for AT-2 citing the system mission and inheritance from common controls
  • Training records retained in the learning management system
  • Attestation records signed at onboarding and annually
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
Where this commonly fails
  • Contractors and third parties not enrolled in mandatory training
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
AT-2(2)
Insider Threat

Include insider threat recognition and reporting in awareness training.

Artefacts an auditor will ask for
  • Insider threat module
Where this commonly fails
  • Module absent
AT-2(3)
Social Engineering and Mining

Include social engineering and social mining recognition in training.

Artefacts an auditor will ask for
  • Phishing simulation results
Where this commonly fails
  • No phishing tests
AT-3
Role-Based Training

Provide role-based security training to personnel with significant security responsibilities before authorizing access and annually.

Artefacts an auditor will ask for
  • Control implementation statement for AT-3 citing the system mission and inheritance from common controls
  • Attestation records signed at onboarding and annually
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
  • Phishing simulation results with click and reporting rates
  • Insider threat awareness briefing materials
Where this commonly fails
  • Contractors and third parties not enrolled in mandatory training
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
  • Training content not reviewed annually for current threat trends
AT-4
Training Records

Document and monitor security training; retain records for FedRAMP-defined period (5 years).

Artefacts an auditor will ask for
  • Control implementation statement for AT-4 citing the system mission and inheritance from common controls
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
  • Phishing simulation results with click and reporting rates
  • Insider threat awareness briefing materials
Where this commonly fails
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
  • Training content not reviewed annually for current threat trends

AU - Audit and Accountability

AU-1
Policy and Procedures

Develop and review audit/accountability policy annually.

Artefacts an auditor will ask for
  • Control implementation statement for AU-1 citing the system mission and inheritance from common controls
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
Where this commonly fails
  • Audit log retention shorter than the policy mandated period
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
AU-10
Non-Repudiation

Provide irrefutable evidence that an entity performed an action; HIGH baseline.

Artefacts an auditor will ask for
  • Digital signature on logs
  • Action attribution
Where this commonly fails
  • No non-repudiation mechanism
AU-11
Audit Record Retention

Retain audit records for at least one year (FedRAMP minimum) with 90 days immediately accessible online.

Artefacts an auditor will ask for
  • Control implementation statement for AU-11 citing the system mission and inheritance from common controls
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-12
Audit Record Generation

Provide audit record generation capability on all system components specified in AU-2.

Artefacts an auditor will ask for
  • Control implementation statement for AU-12 citing the system mission and inheritance from common controls
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-12(1)
System-wide and Time-correlated Audit Trail

Compile audit records into system-wide audit trail that is time-correlated within FedRAMP tolerance.

Artefacts an auditor will ask for
  • Time-correlation evidence
Where this commonly fails
  • Clock drift
AU-12(3)
Changes by Authorized Individuals

Permit authorized individuals to change audit logging selectively for FedRAMP-defined events within defined time thresholds.

Artefacts an auditor will ask for
  • Audit config change records
Where this commonly fails
  • No change tracking
AU-2
Event Logging

Identify event types selected for logging including FedRAMP minimum list; review and update at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for AU-2 citing the system mission and inheritance from common controls
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Audit log retention shorter than the policy mandated period
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
AU-3
Content of Audit Records

Audit records must contain: type, when, where, source, outcome, identity associated.

Artefacts an auditor will ask for
  • Control implementation statement for AU-3 citing the system mission and inheritance from common controls
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
AU-3(1)
Additional Audit Information

Generate audit records containing FedRAMP-defined additional information (session, host, full text of executed commands).

Artefacts an auditor will ask for
  • Enriched log sample
Where this commonly fails
  • Command text not captured
AU-4
Audit Log Storage Capacity

Allocate audit log storage capacity to accommodate FedRAMP-defined retention period.

Artefacts an auditor will ask for
  • Control implementation statement for AU-4 citing the system mission and inheritance from common controls
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-5
Response to Audit Logging Process Failures

Alert defined personnel on audit failure within FedRAMP timeframe; take defined action (overwrite oldest, shutdown, stop processing).

Artefacts an auditor will ask for
  • Control implementation statement for AU-5 citing the system mission and inheritance from common controls
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
AU-5(1)
Storage Capacity Warning

Provide warning within FedRAMP-defined time period when storage capacity reaches 75 percent.

Artefacts an auditor will ask for
  • 75% alert config
Where this commonly fails
  • No threshold warning
AU-5(2)
Real-Time Alerts

Provide alert within real time when FedRAMP-defined audit failure events occur.

Artefacts an auditor will ask for
  • Real-time alerting evidence
Where this commonly fails
  • Batch-only alerting
AU-6
Audit Record Review, Analysis, and Reporting

Review and analyze audit records at least weekly (FedRAMP); report findings to defined personnel.

Artefacts an auditor will ask for
  • Control implementation statement for AU-6 citing the system mission and inheritance from common controls
  • Log review procedures with assigned analyst owners
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
  • Audit log retention shorter than the policy mandated period
AU-6(1)
Automated Process Integration

Integrate audit review with automated mechanisms (SIEM).

Artefacts an auditor will ask for
  • SIEM screenshot
Where this commonly fails
  • No SIEM
AU-6(3)
Correlate Audit Record Repositories

Analyze and correlate audit records across different repositories.

Artefacts an auditor will ask for
  • SIEM correlation rules
Where this commonly fails
  • Siloed logs
AU-6(4)
Central Review and Analysis

Centralized review and analysis of audit records across system components; required at HIGH.

Artefacts an auditor will ask for
  • Central log architecture
Where this commonly fails
  • Per-host logs only
AU-6(5)
Integrated Analysis of Audit Records

Integrate analysis of audit records with analysis of vulnerability scanning, performance data, network monitoring; HIGH only.

Artefacts an auditor will ask for
  • Integrated analytics platform
Where this commonly fails
  • No integration
AU-6(6)
Correlation with Physical Monitoring

Correlate logical audit records with physical access records.

Artefacts an auditor will ask for
  • Badge-system integration
Where this commonly fails
  • Physical access not correlated
AU-6(7)
Permitted Actions

Specify permitted actions for users, roles, processes associated with reviewing audit records.

Artefacts an auditor will ask for
  • Audit reviewer role list
Where this commonly fails
  • No defined reviewer roles
AU-7
Audit Record Reduction and Report Generation

Provide capability for audit record reduction and on-demand report generation.

Artefacts an auditor will ask for
  • Control implementation statement for AU-7 citing the system mission and inheritance from common controls
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-7(1)
Automatic Processing

Process audit records for events of interest based on defined criteria.

Artefacts an auditor will ask for
  • SIEM use cases
Where this commonly fails
  • No detection rules
AU-8
Time Stamps

Use internal system clocks; record timestamps with FedRAMP-defined granularity (1 second), UTC or known offset.

Artefacts an auditor will ask for
  • Control implementation statement for AU-8 citing the system mission and inheritance from common controls
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
  • Audit log retention shorter than the policy mandated period
AU-9
Protection of Audit Information

Protect audit information and tools from unauthorized access, modification, deletion.

Artefacts an auditor will ask for
  • Control implementation statement for AU-9 citing the system mission and inheritance from common controls
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
  • Audit log retention shorter than the policy mandated period
AU-9(2)
Store on Separate Physical Systems or Components

Store audit records on separate physical system/component at least weekly (FedRAMP).

Artefacts an auditor will ask for
  • Off-host log shipping
  • Replication evidence
Where this commonly fails
  • Local-only logs
AU-9(3)
Cryptographic Protection

Cryptographically protect integrity of audit information; HIGH only.

Artefacts an auditor will ask for
  • Log signing/hashing config
Where this commonly fails
  • No log integrity
AU-9(4)
Access by Subset of Privileged Users

Authorize access to audit functionality only to subset of privileged users.

Artefacts an auditor will ask for
  • SIEM role list
Where this commonly fails
  • All admins see all logs

CA - Assessment, Authorization, and Monitoring

CA-1
Policy and Procedures

Develop and review assessment/authorization policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for CA-1 citing the system mission and inheritance from common controls
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
Where this commonly fails
  • Authorization boundary description does not match the asset inventory
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
CA-2
Control Assessments

Assess controls annually (FedRAMP); third-party assessor (3PAO) required; produce SAR.

Artefacts an auditor will ask for
  • Control implementation statement for CA-2 citing the system mission and inheritance from common controls
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • Authorization boundary description does not match the asset inventory
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
CA-2(1)
Independent Assessors

Employ independent assessors; FedRAMP-accredited 3PAO required.

Artefacts an auditor will ask for
  • 3PAO accreditation
  • Independence statement
Where this commonly fails
  • Non-accredited assessor
CA-2(2)
Specialized Assessments

Conduct specialized assessments (announced/unannounced, in-depth, malicious user, penetration testing) at FedRAMP defined frequency.

Artefacts an auditor will ask for
  • Specialized assessment plan
Where this commonly fails
  • No malicious user testing
CA-2(3)
Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]

Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]

Artefacts an auditor will ask for
  • Leverage decision memo
Where this commonly fails
  • No reciprocity documentation
CA-3
Information Exchange

Approve and manage exchange of information with external systems using ISA, MOU, contract; review annually.

Artefacts an auditor will ask for
  • Control implementation statement for CA-3 citing the system mission and inheritance from common controls
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
CA-3(6)
Information Exchange | Transfer Authorizations

Verify that individuals or systems transferring data between interconnecting systems hold the requisite authorizations, meaning write permissions or privileges, before accepting such data.

Artefacts an auditor will ask for
  • Interconnection security agreements naming the parties authorised to transfer data
  • Authorisation records for the systems and individuals permitted to write across each interconnection
  • Evidence that write permission is checked before data is accepted
Where this commonly fails
  • Interconnection agreements exist but nothing checks that the transferring party is authorised
  • Authorisations never re-reviewed after the interconnection goes live
CA-5
Plan of Action and Milestones

Develop POAM; update at least monthly (FedRAMP); track remediation timelines (HIGH 30 days, MOD 90).

Artefacts an auditor will ask for
  • Control implementation statement for CA-5 citing the system mission and inheritance from common controls
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
Where this commonly fails
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
CA-6
Authorization

Senior official authorizes system; reauthorize every three years or upon significant change.

Artefacts an auditor will ask for
  • Control implementation statement for CA-6 citing the system mission and inheritance from common controls
  • Authorization to operate memorandum signed by the authorizing official
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
Where this commonly fails
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
  • Authorization boundary description does not match the asset inventory
CA-7
Continuous Monitoring

Establish continuous monitoring strategy with FedRAMP-defined metrics, monitoring frequencies, ongoing assessments.

Artefacts an auditor will ask for
  • Control implementation statement for CA-7 citing the system mission and inheritance from common controls
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
Where this commonly fails
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
CA-7(1)
Independent Assessment

Employ independent assessors for ongoing monitoring; FedRAMP 3PAO annual.

Artefacts an auditor will ask for
  • 3PAO ConMon engagement
Where this commonly fails
  • No independent ConMon
CA-7(4)
Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring

Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring

Artefacts an auditor will ask for
  • Risk monitoring procedure
  • Risk register
  • Change-driven re-assessments
Where this commonly fails
  • Risk monitoring siloed
  • No change triggers
  • Register stale
CA-8
Penetration Testing

Conduct penetration testing annually on FedRAMP-defined systems and components.

Artefacts an auditor will ask for
  • Control implementation statement for CA-8 citing the system mission and inheritance from common controls
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
  • Authorization boundary description does not match the asset inventory
CA-8(1)
Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components

Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components

Artefacts an auditor will ask for
  • Independent firm SOW
Where this commonly fails
  • Internal team only
CA-8(2)
Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]

Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]

Artefacts an auditor will ask for
  • Red team report
Where this commonly fails
  • No red team activity
CA-9
Internal System Connections

Authorize internal connections of components to system; document interface characteristics.

Artefacts an auditor will ask for
  • Control implementation statement for CA-9 citing the system mission and inheritance from common controls
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
  • Authorization boundary description does not match the asset inventory

CM - Configuration Management

CM-1
Policy and Procedures

Develop and review configuration management policy annually.

Artefacts an auditor will ask for
  • Control implementation statement for CM-1 citing the system mission and inheritance from common controls
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Asset inventory missing cloud workloads and ephemeral resources
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
CM-10
Software Usage Restrictions

Use software in accordance with contracts and copyright laws; track licenses; document peer-to-peer file sharing controls.

Artefacts an auditor will ask for
  • Control implementation statement for CM-10 citing the system mission and inheritance from common controls
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-11
User-Installed Software

Establish policies governing installation of software by users; enforce; monitor compliance.

Artefacts an auditor will ask for
  • Control implementation statement for CM-11 citing the system mission and inheritance from common controls
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
CM-12
Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is processed and stored; b. Identify and document the users who have access

Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is processed and stored; b. Identify and document the users who have access

Artefacts an auditor will ask for
  • Data location map
Where this commonly fails
  • No data inventory
CM-12(1)
Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational

Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational

Artefacts an auditor will ask for
  • DLP/discovery tool
Where this commonly fails
  • No data discovery
CM-14
Signed Components

Prevent the installation of FedRAMP-defined software and firmware components without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.

Artefacts an auditor will ask for
  • Code-signing policy naming the approved certificate authorities
  • Configuration showing signature enforcement at install time
  • Exception register for unsigned components with compensating controls
Where this commonly fails
  • Signature checking enforced on servers but not on build agents or container images
  • Approved certificate list not maintained, so revoked signers still pass
CM-2
Baseline Configuration

Develop and maintain baseline configurations; review and update annually (FedRAMP) and when required.

Artefacts an auditor will ask for
  • Control implementation statement for CM-2 citing the system mission and inheritance from common controls
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Asset inventory missing cloud workloads and ephemeral resources
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-2(2)
Automation Support for Accuracy and Currency

Maintain baseline currency via automated mechanisms.

Artefacts an auditor will ask for
  • CMDB auto-discovery
Where this commonly fails
  • Manual CMDB
CM-2(3)
Retention of Previous Configurations

Retain FedRAMP-defined number of previous baseline configurations (3) to support rollback.

Artefacts an auditor will ask for
  • Snapshot history
Where this commonly fails
  • No rollback capability
CM-2(7)
Configure Systems and Components for High-Risk Areas

Issue systems/devices with FedRAMP-defined security safeguards to individuals traveling to high-risk locations.

Artefacts an auditor will ask for
  • Travel laptop policy
Where this commonly fails
  • No travel device program
CM-3
Configuration Change Control

Determine, document, and approve changes; track, review, audit; CAB or equivalent; analyze security impact.

Artefacts an auditor will ask for
  • Control implementation statement for CM-3 citing the system mission and inheritance from common controls
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-3(1)
Automated Documentation, Notification, and Prohibition

Use automated mechanisms to document, notify approvers, and prohibit changes until approved.

Artefacts an auditor will ask for
  • Workflow tool config
Where this commonly fails
  • Manual approval emails
CM-3(2)
Testing, Validation, and Documentation of Changes

Test, validate, and document changes before implementing on operational system.

Artefacts an auditor will ask for
  • Test plan
  • Validation results
Where this commonly fails
  • No pre-prod testing
CM-3(4)
Security and Privacy Representatives

Require security and privacy representatives on change board for FedRAMP-defined configuration changes.

Artefacts an auditor will ask for
  • CAB roster
Where this commonly fails
  • No security on CAB
CM-3(6)
Cryptography Management

Ensure cryptographic mechanisms providing FedRAMP-defined safeguards are under configuration management.

Artefacts an auditor will ask for
  • Crypto inventory
Where this commonly fails
  • Untracked crypto
CM-4
Impact Analyses

Analyze changes to determine potential security/privacy impacts.

Artefacts an auditor will ask for
  • Control implementation statement for CM-4 citing the system mission and inheritance from common controls
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
CM-4(1)
Separate Test Environments

Analyze changes in separate test environment before implementation; HIGH baseline.

Artefacts an auditor will ask for
  • Test environment diagram
Where this commonly fails
  • No separate test environment
CM-4(2)
Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements

Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements

Artefacts an auditor will ask for
  • Post-change verification reports
  • Control testing results
  • Tickets linking change to verification
Where this commonly fails
  • No post-change testing
  • Verification not documented
  • Controls drift after change
CM-5
Access Restrictions for Change

Define, document, approve, enforce physical and logical access restrictions for changes.

Artefacts an auditor will ask for
  • Control implementation statement for CM-5 citing the system mission and inheritance from common controls
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-5(1)
Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions

Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions

Artefacts an auditor will ask for
  • Deploy logs
Where this commonly fails
  • No deploy audit trail
CM-5(5)
Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment:

Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment:

Artefacts an auditor will ask for
  • Documented list of privileges that permit change to system components and system related information in the production or operational environment
  • Identification of the accounts and roles holding those privileges, extracted from the production environment itself
  • Configuration evidence that developers and other non-operational roles cannot change production components
  • User privilege review records at the defined frequency, showing privileges reviewed and reevaluated
  • Records of privileges removed or reduced as a result of a review
Where this commonly fails
  • Break glass and deployment service accounts excluded from the review, though they carry the strongest change privilege
  • Review confirms the list is unchanged rather than reevaluating whether each privilege is still justified
  • Change privilege limited in the application while underlying platform, container or infrastructure as code paths remain open
CM-6
Configuration Settings

Establish/document configuration settings using checklists; CIS/USGCB/DISA STIG when available; HIGH baseline.

Artefacts an auditor will ask for
  • Control implementation statement for CM-6 citing the system mission and inheritance from common controls
  • Configuration drift detection reports from the CMDB or tooling
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
  • Asset inventory missing cloud workloads and ephemeral resources
CM-6(1)
Automated Management, Application, and Verification

Manage, apply, and verify configuration settings via automated mechanisms; HIGH only.

Artefacts an auditor will ask for
  • IaC pipelines
  • Compliance scanner
Where this commonly fails
  • Manual config
CM-6(2)
Respond to Unauthorized Changes

Take FedRAMP-defined actions in response to unauthorized changes; HIGH only.

Artefacts an auditor will ask for
  • Drift response procedure
Where this commonly fails
  • No drift remediation
CM-7
Least Functionality

Configure system to provide only essential capabilities; prohibit unnecessary functions, services, ports, protocols.

Artefacts an auditor will ask for
  • Control implementation statement for CM-7 citing the system mission and inheritance from common controls
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
CM-7(1)
Periodic Review

Review system functions, ports, protocols, services at least monthly (FedRAMP); disable as unnecessary.

Artefacts an auditor will ask for
  • Monthly review records
Where this commonly fails
  • Annual-only review
CM-7(2)
Prevent Program Execution

Prevent program execution according to FedRAMP-defined policies (rules of behavior).

Artefacts an auditor will ask for
  • App control policy
Where this commonly fails
  • No application control
CM-7(5)
Authorized Software Allow-by-Exception

Identify and maintain authorized software list; employ allowlist; review at least annually; HIGH requirement.

Artefacts an auditor will ask for
  • Allowlist policy
  • Annual review
Where this commonly fails
  • No allowlisting
CM-8
System Component Inventory

Develop and document inventory of system components; review and update at least monthly (FedRAMP).

Artefacts an auditor will ask for
  • Control implementation statement for CM-8 citing the system mission and inheritance from common controls
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
  • Asset inventory missing cloud workloads and ephemeral resources
CM-8(1)
Updates During Installation and Removal

Update inventory as part of component installations, removals, updates.

Artefacts an auditor will ask for
  • Installation workflow
Where this commonly fails
  • Manual inventory
CM-8(2)
Automated Maintenance

Maintain inventory via automated mechanisms; HIGH baseline.

Artefacts an auditor will ask for
  • Auto-discovery tool
Where this commonly fails
  • Spreadsheet-based CMDB
CM-8(3)
Automated Unauthorized Component Detection

Employ automated mechanisms to detect unauthorized components at FedRAMP-defined frequency; HIGH only continuous.

Artefacts an auditor will ask for
  • NAC alerts
  • Rogue device reports
Where this commonly fails
  • No rogue detection
CM-8(4)
Accountability Information

Include in inventory information about owner, position, role responsible for component; HIGH only.

Artefacts an auditor will ask for
  • Owner field in CMDB
Where this commonly fails
  • No accountability assigned
CM-9
Configuration Management Plan

Develop, document, implement configuration management plan addressing roles, processes, items under CM, identification scheme.

Artefacts an auditor will ask for
  • Control implementation statement for CM-9 citing the system mission and inheritance from common controls
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
  • Asset inventory missing cloud workloads and ephemeral resources

CP - Contingency Planning

CP-1
Policy and Procedures

Develop and review contingency planning policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for CP-1 citing the system mission and inheritance from common controls
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Backups taken but restore tests never performed end to end
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
CP-10
System Recovery and Reconstitution

Provide for recovery and reconstitution of system to known state within RTO.

Artefacts an auditor will ask for
  • Control implementation statement for CP-10 citing the system mission and inheritance from common controls
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-10(2)
System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based

System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based

Artefacts an auditor will ask for
  • DB transaction logs
Where this commonly fails
  • No transaction replay
CP-10(4)
Restore Within Time Period

Provide capability to restore system components within FedRAMP-defined time period from configuration-controlled and integrity-protected information; HIGH only.

Artefacts an auditor will ask for
  • Restore drill metrics
Where this commonly fails
  • Untimed restore
CP-2
Contingency Plan

Develop contingency plan; review and update annually (FedRAMP); coordinate with related plans.

Artefacts an auditor will ask for
  • Control implementation statement for CP-2 citing the system mission and inheritance from common controls
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Backups taken but restore tests never performed end to end
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
CP-2(1)
Coordinate with Related Plans

Coordinate contingency plan with related plans (BCP, DRP, COOP, IRP).

Artefacts an auditor will ask for
  • Coordination matrix
Where this commonly fails
  • Siloed plans
CP-2(2)
Capacity Planning

Conduct capacity planning so necessary capacity exists during contingency operations; HIGH baseline.

Artefacts an auditor will ask for
  • Capacity model
Where this commonly fails
  • No capacity for failover
CP-2(3)
Resume Mission and Business Functions

Plan for resumption of mission/business functions within FedRAMP-defined time period after contingency plan activation.

Artefacts an auditor will ask for
  • RTO documentation
Where this commonly fails
  • RTO undefined
CP-2(5)
Continue Mission and Business Functions

Plan for continuation of essential mission/business functions with little or no loss of operational continuity; HIGH only.

Artefacts an auditor will ask for
  • Hot-site capability
Where this commonly fails
  • No continuous capability
CP-2(8)
Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions

Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions

Artefacts an auditor will ask for
  • BIA criticality map
Where this commonly fails
  • No criticality tiers
CP-3
Contingency Training

Provide contingency training to users assigned roles; within FedRAMP timeframe of role assignment and at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for CP-3 citing the system mission and inheritance from common controls
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
Where this commonly fails
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-3(1)
Simulated Events

Incorporate simulated events into contingency training to facilitate effective response; HIGH only.

Artefacts an auditor will ask for
  • Tabletop exercise
Where this commonly fails
  • No simulations
CP-4
Contingency Plan Testing

Test contingency plan at least annually (FedRAMP) using FedRAMP-defined tests; review test results.

Artefacts an auditor will ask for
  • Control implementation statement for CP-4 citing the system mission and inheritance from common controls
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
Where this commonly fails
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
CP-4(1)
Coordinate with Related Plans

Coordinate contingency plan testing with related plan testing.

Artefacts an auditor will ask for
  • Joint test plan
Where this commonly fails
  • Independent testing only
CP-4(2)
Alternate Processing Site

Test contingency plan at alternate processing site; HIGH baseline.

Artefacts an auditor will ask for
  • Failover test results
Where this commonly fails
  • Never failed over
CP-6
Alternate Storage Site

Establish alternate storage site with agreements to permit storage and retrieval of system backup information.

Artefacts an auditor will ask for
  • Control implementation statement for CP-6 citing the system mission and inheritance from common controls
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
Where this commonly fails
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-6(1)
Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats

Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats

Artefacts an auditor will ask for
  • Geographic separation evidence
Where this commonly fails
  • Same metro zone
CP-6(2)
Recovery Time and Recovery Point Objectives

Configure alternate storage site to facilitate recovery operations in accordance with RTO/RPO; HIGH only.

Artefacts an auditor will ask for
  • RTO/RPO documentation
Where this commonly fails
  • No RTO/RPO
CP-6(3)
Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions

Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions

Artefacts an auditor will ask for
  • Accessibility analysis
Where this commonly fails
  • No analysis
CP-7
Alternate Processing Site

Establish alternate processing site with agreements for resumption of operations within FedRAMP-defined RTO.

Artefacts an auditor will ask for
  • Control implementation statement for CP-7 citing the system mission and inheritance from common controls
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
  • Backups taken but restore tests never performed end to end
CP-7(1)
Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats

Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats

Artefacts an auditor will ask for
  • Geographic separation
Where this commonly fails
  • Same region
CP-7(2)
Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions

Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions

Artefacts an auditor will ask for
  • Accessibility plan
Where this commonly fails
  • No plan
CP-7(3)
Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives)

Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives)

Artefacts an auditor will ask for
  • SLA priority clause
Where this commonly fails
  • No priority clauses
CP-7(4)
Preparation for Use

Prepare alternate processing site so it is ready to be used as the operational site; HIGH only.

Artefacts an auditor will ask for
  • Hot-site readiness check
Where this commonly fails
  • Cold site only
CP-8
Telecommunications Services

Establish alternate telecommunications services with agreements to permit resumption of system operations.

Artefacts an auditor will ask for
  • Control implementation statement for CP-8 citing the system mission and inheritance from common controls
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-8(1)
Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and (b) Request Telecommunications Service Priority

Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and (b) Request Telecommunications Service Priority

Artefacts an auditor will ask for
  • TSP enrollment
Where this commonly fails
  • No TSP
CP-8(2)
Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services

Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services

Artefacts an auditor will ask for
  • Diverse routing
Where this commonly fails
  • SPOFs unmitigated
CP-8(3)
Separation of Primary and Alternate Providers

Obtain alternate telecommunications services from providers separated from primary providers; HIGH only.

Artefacts an auditor will ask for
  • Carrier diversity
Where this commonly fails
  • Same carrier diff product
CP-8(4)
Provider Contingency Plan

Require primary and alternate telecommunications providers to have contingency plans; review them; HIGH only.

Artefacts an auditor will ask for
  • Carrier BCP review
Where this commonly fails
  • No carrier BCP visibility
CP-9
System Backup

Conduct backups of user-level, system-level, and security-related documentation; FedRAMP-defined frequency (daily incremental, weekly full).

Artefacts an auditor will ask for
  • Control implementation statement for CP-9 citing the system mission and inheritance from common controls
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
Where this commonly fails
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
  • Backups taken but restore tests never performed end to end
  • RTO and RPO targets undefined for tier two systems
CP-9(1)
Testing for Reliability and Integrity

Test backup information annually to verify reliability and integrity.

Artefacts an auditor will ask for
  • Restore test results
Where this commonly fails
  • Backups never restored
CP-9(2)
Test Restoration Using Sampling

Use sample of backup information to restore selected system functions as part of testing; HIGH only.

Artefacts an auditor will ask for
  • Partial restore evidence
Where this commonly fails
  • No sample restores
CP-9(3)
Separate Storage for Critical Information

Store backup copies of critical software in separate facility or fire-rated container not collocated with operational software.

Artefacts an auditor will ask for
  • Offsite backup evidence
Where this commonly fails
  • Backups onsite only
CP-9(5)
Transfer to Alternate Storage Site

Transfer system backup information to alternate storage site at FedRAMP-defined rate (daily incremental, weekly full); HIGH only.

Artefacts an auditor will ask for
  • Replication schedule
Where this commonly fails
  • Weekly only replication
CP-9(8)
System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information]

System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information]

Artefacts an auditor will ask for
  • Backup encryption config
Where this commonly fails
  • Unencrypted backups

IA - Identification and Authentication

IA-1
Policy and Procedures

Develop and review identification and authentication policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for IA-1 citing the system mission and inheritance from common controls
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
Where this commonly fails
  • Default vendor credentials remain on appliances and IoT devices
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
IA-11
Re-Authentication

Require re-authentication when FedRAMP-defined circumstances occur (role change, privilege change, time period elapsed).

Artefacts an auditor will ask for
  • Control implementation statement for IA-11 citing the system mission and inheritance from common controls
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-12
Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a

Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a

Artefacts an auditor will ask for
  • Control implementation statement for IA-12 citing the system mission and inheritance from common controls
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-12(2)
Identity Proofing | Identity Evidence. Require evidence of individual identification be presented to the registration authority

Identity Proofing | Identity Evidence. Require evidence of individual identification be presented to the registration authority

Artefacts an auditor will ask for
  • Evidence collection records
Where this commonly fails
  • Weak proofing evidence
IA-12(3)
Identity Proofing | Identity Evidence Validation and Verification. Require that the presented identity evidence be validated and verified through [Assignment: organizational defined methods of validation and verification]

Identity Proofing | Identity Evidence Validation and Verification. Require that the presented identity evidence be validated and verified through [Assignment: organizational defined methods of validation and verification]

Artefacts an auditor will ask for
  • Validation procedure
Where this commonly fails
  • Self-attested only
IA-12(4)
In-Person Validation and Verification

Require in-person identity verification for IAL3 (HIGH privileged).

Artefacts an auditor will ask for
  • In-person proofing record
Where this commonly fails
  • Remote-only proofing
IA-12(5)
Identity Proofing | Address Confirmation. Require that a [Selection: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address (physical or digital) of record

Identity Proofing | Address Confirmation. Require that a [Selection: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address (physical or digital) of record

Artefacts an auditor will ask for
  • Address confirmation records
Where this commonly fails
  • No address confirmation
IA-2
Identification and Authentication (Organizational Users)

Uniquely identify and authenticate organizational users and associate identity with processes acting on behalf of users.

Artefacts an auditor will ask for
  • Control implementation statement for IA-2 citing the system mission and inheritance from common controls
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Default vendor credentials remain on appliances and IoT devices
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
IA-2(1)
MFA to Privileged Accounts

Implement MFA for access to privileged accounts; phishing-resistant per FedRAMP.

Artefacts an auditor will ask for
  • FIDO2/PIV config
Where this commonly fails
  • SMS OTP only
IA-2(12)
Acceptance of PIV Credentials

Accept and electronically verify Personal Identity Verification credentials.

Artefacts an auditor will ask for
  • PIV reader config
Where this commonly fails
  • No PIV support
IA-2(2)
MFA to Non-Privileged Accounts

Implement MFA for non-privileged accounts; phishing-resistant per FedRAMP.

Artefacts an auditor will ask for
  • MFA coverage report
Where this commonly fails
  • Exemptions persist
IA-2(5)
Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources

Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources

Artefacts an auditor will ask for
  • Group account handling
Where this commonly fails
  • Direct group login
IA-2(6)
Identification and Authentication (organizational Users) | Access to Accounts , separate Device. Implement multi-factor authentication for [Selection (one or more): local; network; remote] access to [Selection (one or more): privileged accounts; non-privileged accounts] such that:

Identification and Authentication (organizational Users) | Access to Accounts , separate Device. Implement multi-factor authentication for [Selection (one or more): local; network; remote] access to [Selection (one or more): privileged accounts; non-privileged accounts] such that:

Artefacts an auditor will ask for
  • Hardware token policy
Where this commonly fails
  • Same-device push only
IA-2(8)
Access to Accounts Replay Resistant

Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.

Artefacts an auditor will ask for
  • Nonce/timestamp auth
Where this commonly fails
  • Replayable tokens
IA-3
Device Identification and Authentication

Uniquely identify and authenticate devices before establishing connection.

Artefacts an auditor will ask for
  • Control implementation statement for IA-3 citing the system mission and inheritance from common controls
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
IA-4
Identifier Management

Manage identifiers; uniquely identify; prevent reuse for FedRAMP-defined period.

Artefacts an auditor will ask for
  • Control implementation statement for IA-4 citing the system mission and inheritance from common controls
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-4(4)
Identifier Management | Identify User Status. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status]

Identifier Management | Identify User Status. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status]

Artefacts an auditor will ask for
  • Identifier schema
Where this commonly fails
  • No status markers
IA-5
Authenticator Management

Manage authenticators; verify identity prior to issuing; establish initial content; protect.

Artefacts an auditor will ask for
  • Control implementation statement for IA-5 citing the system mission and inheritance from common controls
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
IA-5(1)
Password-Based Authentication

Enforce password complexity per NIST SP 800-63B; minimum 12 characters (FedRAMP); compare against breach lists.

Artefacts an auditor will ask for
  • Password policy
  • Breach check integration
Where this commonly fails
  • No breach checking
IA-5(13)
Authenticator Management | Expiration of Cached Authenticators

Prohibit the use of cached authenticators after a FedRAMP-defined time period.

Artefacts an auditor will ask for
  • Configuration setting the cached credential lifetime
  • Exported policy or screenshots showing the enforced expiry
  • Test evidence that a cached authenticator is refused after the period
Where this commonly fails
  • Cached credential expiry left at the operating system default
  • Mobile and offline endpoints excluded from the setting
IA-5(2)
Public Key-Based Authentication

Enforce authorized use of public key-based authentication; validate certificates; map identity to account.

Artefacts an auditor will ask for
  • PKI policy
  • CRL/OCSP config
Where this commonly fails
  • No revocation checking
IA-5(6)
Protection of Authenticators

Protect authenticators commensurate with security category of information they protect.

Artefacts an auditor will ask for
  • Authenticator handling SOP
Where this commonly fails
  • Tokens in cleartext
IA-5(7)
Authenticator Management | No Embedded Unencrypted Static Authenticators. Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage

Authenticator Management | No Embedded Unencrypted Static Authenticators. Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage

Artefacts an auditor will ask for
  • Secret scanning results
  • Vault adoption
Where this commonly fails
  • Hardcoded creds
IA-5(8)
Multiple System Accounts

Implement security safeguards to manage risk of compromise due to individuals having accounts on multiple systems; HIGH only.

Artefacts an auditor will ask for
  • SSO consolidation evidence
Where this commonly fails
  • Separate creds per system
IA-6
Authentication Feedback

Obscure authentication feedback during authentication process.

Artefacts an auditor will ask for
  • Control implementation statement for IA-6 citing the system mission and inheritance from common controls
  • Service account credential vault inventory and rotation logs
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
  • Default vendor credentials remain on appliances and IoT devices
IA-7
Cryptographic Module Authentication

Implement authentication to cryptographic modules meeting FIPS 140 (FedRAMP requires FIPS-validated).

Artefacts an auditor will ask for
  • Control implementation statement for IA-7 citing the system mission and inheritance from common controls
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-8
Identification and Authentication (Non-Organizational Users)

Uniquely identify and authenticate non-organizational users (e.g., federal customers).

Artefacts an auditor will ask for
  • Control implementation statement for IA-8 citing the system mission and inheritance from common controls
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
  • Default vendor credentials remain on appliances and IoT devices
IA-8(1)
Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies. Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies

Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies. Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies

Artefacts an auditor will ask for
  • Cross-agency PIV trust
Where this commonly fails
  • Internal PIV only
IA-8(2)
Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators. (a) Accept only external authenticators that are NIST-compliant; and (b) Document and maintain a list of accepted external authenticators

Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators. (a) Accept only external authenticators that are NIST-compliant; and (b) Document and maintain a list of accepted external authenticators

Artefacts an auditor will ask for
  • FICAM-approved IDP list
Where this commonly fails
  • Non-FICAM IDP
IA-8(4)
Identification and Authentication (non-organizational Users) | Use of Defined Profiles. Conform to the following profiles for identity management [Assignment: organization-defined identity management profiles]

Identification and Authentication (non-organizational Users) | Use of Defined Profiles. Conform to the following profiles for identity management [Assignment: organization-defined identity management profiles]

Artefacts an auditor will ask for
  • Profile documentation
Where this commonly fails
  • No profile mapping

IR - Incident Response

IR-1
Policy and Procedures

Requires an incident response policy and supporting procedures to be developed, documented, disseminated, reviewed and updated on a defined cycle.

Artefacts an auditor will ask for
  • Control implementation statement for IR-1 citing the system mission and inheritance from common controls
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Third party incident responder retainer expired
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-2
Incident Response Training

Requires incident response training for system users consistent with their assigned roles, within a defined period of assuming the role and periodically thereafter.

Artefacts an auditor will ask for
  • Control implementation statement for IR-2 citing the system mission and inheritance from common controls
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Third party incident responder retainer expired
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
IR-2(1)
Simulated Events

Incorporate simulated events into IR training; HIGH only.

Artefacts an auditor will ask for
  • Tabletop records
Where this commonly fails
  • No simulations
IR-2(2)
Automated Training Environments

Provide thorough and realistic IR training via automated mechanisms; HIGH only.

Artefacts an auditor will ask for
  • Cyber range evidence
Where this commonly fails
  • No simulation environment
IR-3
Incident Response Testing

Requires the incident response capability to be tested at a defined frequency using defined tests, to determine its effectiveness, and the results documented.

Artefacts an auditor will ask for
  • Control implementation statement for IR-3 citing the system mission and inheritance from common controls
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
Where this commonly fails
  • Third party incident responder retainer expired
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-3(2)
Incident Response Testing | Coordination with Related Plans. Coordinate incident response testing with organizational elements responsible for related plans

Incident Response Testing | Coordination with Related Plans. Coordinate incident response testing with organizational elements responsible for related plans

Artefacts an auditor will ask for
  • Joint test plan
Where this commonly fails
  • Isolated tests
IR-4
Incident Handling

Implement IR capability for preparation, detection/analysis, containment, eradication, recovery.

Artefacts an auditor will ask for
  • Control implementation statement for IR-4 citing the system mission and inheritance from common controls
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
Where this commonly fails
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-4(1)
Automated Incident Handling Processes

Support incident handling via automated mechanisms.

Artefacts an auditor will ask for
  • SOAR playbooks
Where this commonly fails
  • Manual-only handling
IR-4(11)
Incident Handling | Integrated Incident Response Team

Establish and maintain an integrated incident response team that can be deployed to any location identified by the organization within a FedRAMP-defined time period.

Artefacts an auditor will ask for
  • Incident response team charter with named roles and deployment commitments
  • On-call roster and escalation tree
  • Records of deployment or remote engagement inside the committed period
Where this commonly fails
  • Team is a distribution list rather than named accountable roles
  • No deployment time commitment defined, so it is never measured
IR-4(2)
Incident Handling | Dynamic Reconfiguration

Include FedRAMP-defined types of dynamic reconfiguration for FedRAMP-defined system components as part of the incident response capability.

Artefacts an auditor will ask for
  • Incident response plan section naming the components that can be dynamically reconfigured
  • Runbooks for isolation, rule changes or rerouting during an incident
  • Exercise records showing dynamic reconfiguration actually performed
Where this commonly fails
  • Capability exists technically but is not written into the incident response plan
  • Never exercised, so the achievable change window is unknown
IR-4(4)
Information Correlation

Correlate incident information and individual incident responses for organization-wide perspective; HIGH only.

Artefacts an auditor will ask for
  • Cross-incident analytics
Where this commonly fails
  • No correlation across incidents
IR-4(6)
Insider Threats

Implement incident handling capability for insider threats.

Artefacts an auditor will ask for
  • Insider threat program
Where this commonly fails
  • No insider program
IR-5
Incident Monitoring

Track and document incidents.

Artefacts an auditor will ask for
  • Control implementation statement for IR-5 citing the system mission and inheritance from common controls
  • Incident response team roster with on call rotation
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
Where this commonly fails
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
  • Notification timelines miss jurisdictional regulatory deadlines
IR-5(1)
Automated Tracking, Data Collection, and Analysis

Track incidents and collect/analyze incident information via automated mechanisms; HIGH only.

Artefacts an auditor will ask for
  • SIEM/SOAR integration
Where this commonly fails
  • Manual incident logs
IR-6
Incident Reporting

Require personnel to report incidents to organizational authorities within FedRAMP timeframe; report to FedRAMP PMO and US-CERT.

Artefacts an auditor will ask for
  • Control implementation statement for IR-6 citing the system mission and inheritance from common controls
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
Where this commonly fails
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-6(1)
Automated Reporting

Report incidents via automated mechanisms.

Artefacts an auditor will ask for
  • Automated reporting workflow
Where this commonly fails
  • Manual email reports
IR-6(3)
Incident Reporting | Supply Chain Coordination. Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components

Incident Reporting | Supply Chain Coordination. Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components

Artefacts an auditor will ask for
  • Supplier notification log
Where this commonly fails
  • No supplier coordination
IR-7
Incident Response Assistance

Provide IR support resource (help desk, support group) for incident handling assistance.

Artefacts an auditor will ask for
  • Control implementation statement for IR-7 citing the system mission and inheritance from common controls
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
  • Notification timelines miss jurisdictional regulatory deadlines
  • Third party incident responder retainer expired
IR-7(1)
Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms]

Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms]

Artefacts an auditor will ask for
  • Knowledge base
Where this commonly fails
  • No automated KB
IR-8
Incident Response Plan

Develop and implement IRP; review and update annually; distribute.

Artefacts an auditor will ask for
  • Control implementation statement for IR-8 citing the system mission and inheritance from common controls
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
  • Notification timelines miss jurisdictional regulatory deadlines
IR-9
Information Spillage Response. Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to information spills; b. Identifying the specific information involved in the system contamination; c. Alerting

Information Spillage Response. Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to information spills; b. Identifying the specific information involved in the system contamination; c. Alerting

Artefacts an auditor will ask for
  • Spill response procedure
Where this commonly fails
  • No spill procedure
IR-9(2)
Information Spillage Response | Training. Provide information spillage response training [Assignment: organization-defined frequency]

Information Spillage Response | Training. Provide information spillage response training [Assignment: organization-defined frequency]

Artefacts an auditor will ask for
  • Spill training records
Where this commonly fails
  • No spill training
IR-9(3)
Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks while contaminated systems are undergoing corrective actions: [Assignment:

Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks while contaminated systems are undergoing corrective actions: [Assignment:

Artefacts an auditor will ask for
  • Post-spill procedure
Where this commonly fails
  • Personnel locked out
IR-9(4)
Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls]

Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls]

Artefacts an auditor will ask for
  • Exposure handling SOP
Where this commonly fails
  • No safeguards

MA - Maintenance

MA-1
Policy and Procedures

Develop and review maintenance policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for MA-1 citing the system mission and inheritance from common controls
  • Maintenance personnel access list with background check status
  • Remote maintenance session logs with MFA and supervision evidence
  • Tool sanitisation records for media leaving the facility
  • Vendor maintenance agreements with security clauses
Where this commonly fails
  • Emergency maintenance performed without retrospective documentation
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
MA-2
Controlled Maintenance

Schedule, document, review records of maintenance, repair, replacement of components.

Artefacts an auditor will ask for
  • Control implementation statement for MA-2 citing the system mission and inheritance from common controls
  • Remote maintenance session logs with MFA and supervision evidence
  • Tool sanitisation records for media leaving the facility
  • Vendor maintenance agreements with security clauses
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
Where this commonly fails
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
  • Maintenance tools not sanitised before removal from secure areas
MA-2(2)
Automated Maintenance Activities

Schedule, conduct, document maintenance via automated mechanisms; HIGH only.

Artefacts an auditor will ask for
  • Auto-patching evidence
Where this commonly fails
  • Manual patch logs
MA-3
Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]

Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]

Artefacts an auditor will ask for
  • Control implementation statement for MA-3 citing the system mission and inheritance from common controls
  • Tool sanitisation records for media leaving the facility
  • Vendor maintenance agreements with security clauses
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
Where this commonly fails
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
MA-3(1)
Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications

Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications

Artefacts an auditor will ask for
  • Tool inspection records
Where this commonly fails
  • No inspections
MA-3(2)
Maintenance Tools | Inspect Media. Check media containing diagnostic and test programs for malicious code before the media are used in the system

Maintenance Tools | Inspect Media. Check media containing diagnostic and test programs for malicious code before the media are used in the system

Artefacts an auditor will ask for
  • Media scan logs
Where this commonly fails
  • No media scanning
MA-3(3)
Maintenance Tools | Prevent Unauthorized Removal. Prevent the removal of maintenance equipment containing organizational information by: (a) Verifying that there is no organizational information contained on the equipment; (b) Sanitizing or destroying the equipment;

Maintenance Tools | Prevent Unauthorized Removal. Prevent the removal of maintenance equipment containing organizational information by: (a) Verifying that there is no organizational information contained on the equipment; (b) Sanitizing or destroying the equipment;

Artefacts an auditor will ask for
  • Removal procedure
Where this commonly fails
  • No removal control
MA-4
Nonlocal Maintenance

Approve and monitor nonlocal maintenance activities; use strong authentication.

Artefacts an auditor will ask for
  • Control implementation statement for MA-4 citing the system mission and inheritance from common controls
  • Vendor maintenance agreements with security clauses
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
  • Maintenance personnel access list with background check status
  • Remote maintenance session logs with MFA and supervision evidence
Where this commonly fails
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
  • Maintenance tools not sanitised before removal from secure areas
MA-4(3)
Comparable Security and Sanitization

Require nonlocal maintenance services be performed from component with comparable security; sanitize before/after; HIGH only.

Artefacts an auditor will ask for
  • Sanitization records
Where this commonly fails
  • No sanitization
MA-5
Maintenance Personnel

Establish process for authorizing maintenance personnel; maintain list of authorized personnel; supervise unauthorized.

Artefacts an auditor will ask for
  • Control implementation statement for MA-5 citing the system mission and inheritance from common controls
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
  • Maintenance personnel access list with background check status
  • Remote maintenance session logs with MFA and supervision evidence
Where this commonly fails
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
  • Maintenance tools not sanitised before removal from secure areas
MA-5(1)
Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clearances or are not U.S. citizens, that include the following requirements: (1)

Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clearances or are not U.S. citizens, that include the following requirements: (1)

Artefacts an auditor will ask for
  • Escort procedure
Where this commonly fails
  • Unescorted vendors
MA-6
Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure

Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure

Artefacts an auditor will ask for
  • Support contracts
Where this commonly fails
  • No SLA

MP - Media Protection

MP-1
Policy and Procedures

Develop and review media protection policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for MP-1 citing the system mission and inheritance from common controls
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
Where this commonly fails
  • Backup tapes shipped without tamper evident packaging
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
MP-2
Media Access

Restrict access to FedRAMP-defined types of digital and non-digital media to authorized personnel.

Artefacts an auditor will ask for
  • Control implementation statement for MP-2 citing the system mission and inheritance from common controls
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
Where this commonly fails
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
MP-3
Media Marking

Mark system media indicating distribution limitations, handling caveats, security markings.

Artefacts an auditor will ask for
  • Control implementation statement for MP-3 citing the system mission and inheritance from common controls
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
Where this commonly fails
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
MP-4
Media Storage

Physically control and securely store FedRAMP-defined types of media within FedRAMP-defined controlled areas.

Artefacts an auditor will ask for
  • Control implementation statement for MP-4 citing the system mission and inheritance from common controls
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
Where this commonly fails
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
MP-5
Media Transport

Protect and control media during transport outside controlled areas; maintain accountability; document activities; restrict transport to authorized personnel.

Artefacts an auditor will ask for
  • Control implementation statement for MP-5 citing the system mission and inheritance from common controls
  • Removable media usage policy and DLP enforcement evidence
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
Where this commonly fails
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
  • Backup tapes shipped without tamper evident packaging
MP-6
Media Sanitization

Sanitize media prior to disposal, release, or reuse using FedRAMP-defined methods (NIST SP 800-88).

Artefacts an auditor will ask for
  • Control implementation statement for MP-6 citing the system mission and inheritance from common controls
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
Where this commonly fails
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
MP-6(1)
Review, Approve, Track, Document, Verify

Review, approve, track, document, verify media sanitization and disposal actions.

Artefacts an auditor will ask for
  • Disposal records
Where this commonly fails
  • No verification step
MP-6(2)
Equipment Testing

Test sanitization equipment and procedures at FedRAMP-defined frequency to ensure intended operation.

Artefacts an auditor will ask for
  • Equipment test
Where this commonly fails
  • No equipment tests
MP-6(3)
Nondestructive Techniques

Apply nondestructive sanitization techniques to portable storage devices prior to connecting to system under FedRAMP-defined circumstances.

Artefacts an auditor will ask for
  • Pre-connect wipe procedure
Where this commonly fails
  • No pre-use sanitization
MP-7
Media Use

Restrict or prohibit use of FedRAMP-defined types of media on FedRAMP-defined systems using safeguards.

Artefacts an auditor will ask for
  • Control implementation statement for MP-7 citing the system mission and inheritance from common controls
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
Where this commonly fails
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
  • Backup tapes shipped without tamper evident packaging

PE - Physical and Environmental Protection

PE-1
Policy and Procedures

Develop and review physical/environmental policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for PE-1 citing the system mission and inheritance from common controls
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Visitor logs incomplete or escort sign offs missing
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-10
Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system

Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system

Artefacts an auditor will ask for
  • Control implementation statement for PE-10 citing the system mission and inheritance from common controls
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-11
Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power

Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power

Artefacts an auditor will ask for
  • Control implementation statement for PE-11 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-11(1)
Alternate Power Supply Minimal Operational Capability

Provide alternate power that is self-contained and not reliant on external sources; HIGH only.

Artefacts an auditor will ask for
  • Generator config
Where this commonly fails
  • No generator
PE-12
Emergency Lighting

Employ and maintain automatic emergency lighting activating on power outage covering emergency exits.

Artefacts an auditor will ask for
  • Control implementation statement for PE-12 citing the system mission and inheritance from common controls
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-13
Fire Protection

Employ and maintain fire suppression and detection devices independent of energy source.

Artefacts an auditor will ask for
  • Control implementation statement for PE-13 citing the system mission and inheritance from common controls
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-13(1)
Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a

Fire Protection | Detection Systems. Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a

Artefacts an auditor will ask for
  • Alarm escalation
Where this commonly fails
  • No escalation list
PE-13(2)
Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an

Fire Protection | Suppression Systems. Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an

Artefacts an auditor will ask for
  • Automatic suppression
Where this commonly fails
  • Manual only
PE-14
Environmental Controls

Maintain temperature and humidity within FedRAMP-defined acceptable levels; monitor at FedRAMP frequency.

Artefacts an auditor will ask for
  • Control implementation statement for PE-14 citing the system mission and inheritance from common controls
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
  • Visitor logs incomplete or escort sign offs missing
PE-14(2)
Environmental Controls | Monitoring with Alarms and Notifications

Employ environmental control monitoring that provides an alarm or notification of changes potentially harmful to personnel or equipment to FedRAMP-defined personnel or roles.

Artefacts an auditor will ask for
  • Environmental monitoring configuration showing the alarm thresholds
  • Alarm routing list naming the recipients
  • Alarm test records and sample notifications
Where this commonly fails
  • Monitoring present but alarms route to an unmonitored mailbox
  • Inherited from the data centre provider with no customer responsibility matrix entry evidencing it
PE-15
Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel

Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel

Artefacts an auditor will ask for
  • Control implementation statement for PE-15 citing the system mission and inheritance from common controls
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-15(1)
Automation Support

Detect leaks and alert FedRAMP-defined personnel via automated mechanisms; HIGH only.

Artefacts an auditor will ask for
  • Auto leak sensors
Where this commonly fails
  • Manual checks
PE-16
Delivery and Removal

Authorize and control system components entering/exiting facility; maintain records.

Artefacts an auditor will ask for
  • Inventory in/out logs
Where this commonly fails
  • No records
PE-17
Alternate Work Site

Determine alternate work sites; employ FedRAMP-defined controls at alternate sites; assess effectiveness.

Artefacts an auditor will ask for
  • Control implementation statement for PE-17 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
  • Visitor logs incomplete or escort sign offs missing
PE-18
Location of System Components

Position system components to minimize damage from physical/environmental hazards and unauthorized access; HIGH only.

Artefacts an auditor will ask for
  • Rack layout
Where this commonly fails
  • High-risk placement
PE-2
Physical Access Authorizations

Develop, approve, maintain list of individuals with authorized facility access; review at least quarterly (FedRAMP).

Artefacts an auditor will ask for
  • Control implementation statement for PE-2 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Visitor logs incomplete or escort sign offs missing
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
PE-3
Physical Access Control

Enforce physical access at entry/exit points; verify authorizations; control ingress/egress; maintain audit logs.

Artefacts an auditor will ask for
  • Control implementation statement for PE-3 citing the system mission and inheritance from common controls
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Visitor logs incomplete or escort sign offs missing
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-3(1)
System Access

Enforce physical access authorizations to system in addition to physical access controls for facility; HIGH only.

Artefacts an auditor will ask for
  • Secondary access controls
Where this commonly fails
  • Facility-only controls
PE-4
Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls]

Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls]

Artefacts an auditor will ask for
  • Control implementation statement for PE-4 citing the system mission and inheritance from common controls
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-5
Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output

Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output

Artefacts an auditor will ask for
  • Control implementation statement for PE-5 citing the system mission and inheritance from common controls
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-6
Monitoring Physical Access

Monitor physical access to facility; review access logs at least weekly (FedRAMP); coordinate review with IR.

Artefacts an auditor will ask for
  • Control implementation statement for PE-6 citing the system mission and inheritance from common controls
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-6(1)
Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment. Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment

Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment. Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment

Artefacts an auditor will ask for
  • CCTV deployment
Where this commonly fails
  • No surveillance
PE-6(4)
Monitoring Physical Access to Systems

Monitor physical access to system in addition to facility access at FedRAMP-defined components; HIGH only.

Artefacts an auditor will ask for
  • Cage/rack camera
Where this commonly fails
  • Only facility monitored
PE-8
Visitor Access Records

Maintain visitor access records for FedRAMP-defined period (1 year); review records monthly (FedRAMP).

Artefacts an auditor will ask for
  • Control implementation statement for PE-8 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-8(1)
Automated Records Maintenance and Review

Maintain and review visitor access records via automated mechanisms; HIGH only.

Artefacts an auditor will ask for
  • Visitor mgmt system
Where this commonly fails
  • Paper log
PE-9
Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction

Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction

Artefacts an auditor will ask for
  • Control implementation statement for PE-9 citing the system mission and inheritance from common controls
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
  • Visitor logs incomplete or escort sign offs missing

PL - Planning

PL-1
Policy and Procedures

Develop and review planning policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for PL-1 citing the system mission and inheritance from common controls
  • Concept of operations describing system mission and data flows
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
Where this commonly fails
  • Planning artefacts lack version history and approval signatures
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
PL-10
Baseline Selection. Select a control baseline for the system

Baseline Selection. Select a control baseline for the system

Artefacts an auditor will ask for
  • Control implementation statement for PL-10 citing the system mission and inheritance from common controls
  • Concept of operations describing system mission and data flows
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
Where this commonly fails
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
PL-11
Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions

Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions

Artefacts an auditor will ask for
  • Control implementation statement for PL-11 citing the system mission and inheritance from common controls
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
Where this commonly fails
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
  • Architecture diagrams missing third party and SaaS dependencies
PL-2
System Security and Privacy Plans

Develop SSP that aligns with FedRAMP template; review and update annually.

Artefacts an auditor will ask for
  • Control implementation statement for PL-2 citing the system mission and inheritance from common controls
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
Where this commonly fails
  • Planning artefacts lack version history and approval signatures
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
PL-4
Rules of Behavior

Establish and provide rules describing user responsibilities; receive signed acknowledgement.

Artefacts an auditor will ask for
  • Control implementation statement for PL-4 citing the system mission and inheritance from common controls
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
  • Concept of operations describing system mission and data flows
  • Privacy and security integration documentation
Where this commonly fails
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
  • Architecture diagrams missing third party and SaaS dependencies
PL-4(1)
Rules of Behavior | Social Media and External Site/application Usage Restrictions. Include in the rules of behavior, restrictions on: (a) Use of social media, social networking sites, and external sites/applications; (b) Posting organizational information

Rules of Behavior | Social Media and External Site/application Usage Restrictions. Include in the rules of behavior, restrictions on: (a) Use of social media, social networking sites, and external sites/applications; (b) Posting organizational information

Artefacts an auditor will ask for
  • Social media clause
Where this commonly fails
  • Generic RoB
PL-8
Security and Privacy Architectures

Develop, document, maintain security/privacy architectures; review annually.

Artefacts an auditor will ask for
  • Control implementation statement for PL-8 citing the system mission and inheritance from common controls
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
Where this commonly fails
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
  • Architecture diagrams missing third party and SaaS dependencies
  • Planning artefacts lack version history and approval signatures

PS - Personnel Security

PS-1
Policy and Procedures

Develop and review personnel security policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for PS-1 citing the system mission and inheritance from common controls
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Background checks not re run when employees move to higher risk roles
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
PS-2
Position Risk Designation

Assign risk designation to positions; review and update at least every three years.

Artefacts an auditor will ask for
  • Control implementation statement for PS-2 citing the system mission and inheritance from common controls
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
PS-3
Personnel Screening

Screen individuals prior to authorizing access; rescreen at FedRAMP frequency per position risk; US citizenship may apply.

Artefacts an auditor will ask for
  • Control implementation statement for PS-3 citing the system mission and inheritance from common controls
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
Where this commonly fails
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
PS-3(3)
Personnel Screening | Information Requiring Special Protective Measures. Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection: (a) Have valid access authorizations that are demonstrated by assigned official government

Personnel Screening | Information Requiring Special Protective Measures. Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection: (a) Have valid access authorizations that are demonstrated by assigned official government

Artefacts an auditor will ask for
  • Special access agreements
Where this commonly fails
  • No special handling
PS-4
Personnel Termination

Disable access and revoke authenticators within FedRAMP-defined time (same day); conduct exit interview; retrieve property.

Artefacts an auditor will ask for
  • Control implementation statement for PS-4 citing the system mission and inheritance from common controls
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
Where this commonly fails
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
PS-4(2)
Automated Actions

Use automated mechanisms to notify defined personnel upon termination and disable access; HIGH only.

Artefacts an auditor will ask for
  • HR-IAM integration
Where this commonly fails
  • Manual offboarding
PS-5
Personnel Transfer

Review/confirm ongoing operational need for access when personnel transfer; modify access; notify within FedRAMP timeframe.

Artefacts an auditor will ask for
  • Control implementation statement for PS-5 citing the system mission and inheritance from common controls
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
Where this commonly fails
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
PS-6
Access Agreements

Develop access agreements; review and update annually; require signature before access.

Artefacts an auditor will ask for
  • Control implementation statement for PS-6 citing the system mission and inheritance from common controls
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
Where this commonly fails
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
PS-7
External Personnel Security

Establish personnel security requirements for external providers; require providers to notify within FedRAMP timeframe of personnel changes.

Artefacts an auditor will ask for
  • Control implementation statement for PS-7 citing the system mission and inheritance from common controls
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
PS-8
Personnel Sanctions

Employ formal sanctions for personnel failing to comply with security/privacy policies; notify defined personnel within FedRAMP timeframe.

Artefacts an auditor will ask for
  • Control implementation statement for PS-8 citing the system mission and inheritance from common controls
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
PS-9
Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions

Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions

Artefacts an auditor will ask for
  • Control implementation statement for PS-9 citing the system mission and inheritance from common controls
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
Where this commonly fails
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
  • Termination access removal exceeds documented SLA

RA - Risk Assessment

RA-1
Policy and Procedures

Develop and review risk assessment policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for RA-1 citing the system mission and inheritance from common controls
  • Risk register with likelihood, impact, and treatment owners
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
Where this commonly fails
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
RA-2
Security Categorization

Categorize system per FIPS 199; document; review and update annually.

Artefacts an auditor will ask for
  • Control implementation statement for RA-2 citing the system mission and inheritance from common controls
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
Where this commonly fails
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
RA-3
Risk Assessment

Conduct risk assessment annually (FedRAMP); document; review and update.

Artefacts an auditor will ask for
  • Control implementation statement for RA-3 citing the system mission and inheritance from common controls
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
  • Risk assessment methodology approved by leadership
  • Risk register with likelihood, impact, and treatment owners
Where this commonly fails
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
RA-3(1)
Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; and (b) Update the supply chain risk assessment [Assignment: organization-defined frequency], when

Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; and (b) Update the supply chain risk assessment [Assignment: organization-defined frequency], when

Artefacts an auditor will ask for
  • SCRM assessment
Where this commonly fails
  • No SCRM
RA-5
Vulnerability Monitoring and Scanning

Scan for vulnerabilities monthly (FedRAMP); OS/network weekly, web app monthly, database monthly; remediate within FedRAMP timeframes (HIGH critical 15d, high 30d).

Artefacts an auditor will ask for
  • Control implementation statement for RA-5 citing the system mission and inheritance from common controls
  • Risk acceptance memos signed by accountable executives
  • Risk assessment methodology approved by leadership
  • Risk register with likelihood, impact, and treatment owners
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
Where this commonly fails
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
RA-5(11)
Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components

Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components

Artefacts an auditor will ask for
  • VDP page
  • Triage SOP
Where this commonly fails
  • No VDP
RA-5(2)
Update Vulnerabilities to be Scanned

Update vulnerability list prior to scan, when new vulnerabilities identified, or at FedRAMP frequency.

Artefacts an auditor will ask for
  • Scanner update schedule
Where this commonly fails
  • Stale signatures
RA-5(3)
Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage

Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage

Artefacts an auditor will ask for
  • The documented definition of breadth and depth of vulnerability scanning coverage, stating which components and which vulnerability classes are in scope
  • Scanner configuration showing the target scope and the checks enabled, matched against that definition
  • Scan results demonstrating the defined breadth was actually reached, with an accounted list of assets not scanned
  • Reconciliation of scan targets against the system component inventory
  • Evidence of authenticated scanning where depth requires it, and the credentials scope used
Where this commonly fails
  • Breadth and depth asserted from the tool default rather than defined by the organisation, which is exactly what this enhancement requires
  • Scan coverage never reconciled against the asset inventory, so unscanned hosts are invisible
  • Unauthenticated scanning presented as satisfying depth, missing configuration and patch level findings
RA-5(4)
Discoverable Information

Determine what information about system is discoverable and take corrective actions; HIGH only.

Artefacts an auditor will ask for
  • OSINT analysis
Where this commonly fails
  • No external recon
RA-5(5)
Privileged Access

Implement privileged access authorization to FedRAMP-defined components for vulnerability scanning.

Artefacts an auditor will ask for
  • Authenticated scan config
Where this commonly fails
  • Unauthenticated scans only
RA-5(8)
Vulnerability Monitoring and Scanning | Review Historic Audit Logs

Review historic audit logs to determine if a vulnerability identified in a FedRAMP-defined system has been previously exploited within a FedRAMP-defined time period.

Artefacts an auditor will ask for
  • Procedure linking a new vulnerability finding to a retrospective log review
  • Log retention evidence covering the defined lookback period
  • Completed retrospective reviews with their conclusions
Where this commonly fails
  • Log retention shorter than the lookback period the procedure claims
  • Retrospective review done only after a major incident rather than as routine
RA-7
Risk Response

Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so identified risk is treated rather than only recorded.

Artefacts an auditor will ask for
  • Control implementation statement for RA-7 citing the system mission and inheritance from common controls
  • Risk register with likelihood, impact, and treatment owners
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
Where this commonly fails
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
RA-9
Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or system services] at [Assignment: organization-defined decision points in the system development life cycle]

Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or system services] at [Assignment: organization-defined decision points in the system development life cycle]

Artefacts an auditor will ask for
  • Control implementation statement for RA-9 citing the system mission and inheritance from common controls
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
  • Risk assessment methodology approved by leadership
  • Risk register with likelihood, impact, and treatment owners
Where this commonly fails
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
  • Risk register entries lack named owner or due date

SA - System and Services Acquisition

SA-1
Policy and Procedures

Requires a system and services acquisition policy and supporting procedures to be developed, documented, disseminated, reviewed and updated on a defined cycle.

Artefacts an auditor will ask for
  • Control implementation statement for SA-1 citing the system mission and inheritance from common controls
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
Where this commonly fails
  • Security requirements absent from procurement templates for low value buys
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
SA-10
Developer Configuration Management

Require developer to perform CM during development, implementation, operation; document/track changes; implement only approved changes.

Artefacts an auditor will ask for
  • Control implementation statement for SA-10 citing the system mission and inheritance from common controls
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
Where this commonly fails
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
SA-11
Developer Testing and Evaluation

Require developer to test at FedRAMP-defined depth and coverage; document; correct flaws.

Artefacts an auditor will ask for
  • Control implementation statement for SA-11 citing the system mission and inheritance from common controls
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
SA-11(1)
Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of

Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of

Artefacts an auditor will ask for
  • SAST results
Where this commonly fails
  • No SAST
SA-11(2)
Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing

Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing

Artefacts an auditor will ask for
  • Threat models
Where this commonly fails
  • No threat modeling
SA-15
Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the

Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the

Artefacts an auditor will ask for
  • Control implementation statement for SA-15 citing the system mission and inheritance from common controls
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
Where this commonly fails
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
  • Threat modelling performed inconsistently across product teams
SA-15(3)
Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At the following decision points in the system development

Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At the following decision points in the system development

Artefacts an auditor will ask for
  • Contract or solicitation clause requiring the developer to perform criticality analysis
  • The developer's criticality analysis output identifying critical components and functions
  • Evidence the analysis was performed at the defined decision points in the development life cycle
  • Evidence the analysis was performed at the defined level of detail or decomposition
  • Organisational review of the developer's analysis and the actions taken on its findings
Where this commonly fails
  • Analysis delivered once at design with no repeat at the later decision points the requirement names
  • Decomposition stopped at the subsystem level, so the critical component inside it is never identified
  • Developer output accepted with no organisational review, so criticality findings drive no acquisition decision
SA-16
Developer-Provided Training

Require developer to provide training on correct use and operation of security/privacy functions; HIGH only.

Artefacts an auditor will ask for
  • Vendor training
Where this commonly fails
  • No training
SA-17
Developer Security and Privacy Architecture and Design

Require developer to produce design specification and security architecture; HIGH only.

Artefacts an auditor will ask for
  • Security architecture
Where this commonly fails
  • No architecture
SA-2
Allocation of Resources

Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning; determine, document and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process; and establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.

Artefacts an auditor will ask for
  • Mission and business process planning documentation recording the high-level information security and privacy requirements determined for the system or system service
  • Capital planning and investment control submission or business case showing the resources determined, documented and allocated to protect the system or system service
  • Programming and budgeting documentation showing a discrete line item for information security and privacy
  • Approved budget or spend plan carrying that line item, with its approval record
  • System security and privacy plan section recording the allocated resources and the basis for the amount
  • Records of review of the allocation when requirements or the system change across the system development life cycle
Where this commonly fails
  • Security and privacy requirements determined after the acquisition decision rather than during mission and business process planning
  • Security funding absorbed into a general IT or infrastructure line, so no discrete information security and privacy item exists to evidence
  • Resources named in a plan but never traced through to an approved budget or capital planning submission
  • Privacy resourcing omitted while security resourcing is documented, although the control covers both
  • Line item established once at authorization and not maintained through sustainment and supply chain activity
SA-21
Developer Screening

Require developer of FedRAMP-defined components to have personnel access authorizations and screening; HIGH only.

Artefacts an auditor will ask for
  • Developer screening
Where this commonly fails
  • No screening
SA-22
Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support

Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support

Artefacts an auditor will ask for
  • Control implementation statement for SA-22 citing the system mission and inheritance from common controls
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
Where this commonly fails
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
SA-3
System Development Life Cycle

Manage system using SDLC incorporating security/privacy considerations.

Artefacts an auditor will ask for
  • Control implementation statement for SA-3 citing the system mission and inheritance from common controls
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
SA-4
Acquisition Process

Include security/privacy requirements in contracts; FedRAMP-defined assurance requirements.

Artefacts an auditor will ask for
  • Control implementation statement for SA-4 citing the system mission and inheritance from common controls
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
Where this commonly fails
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
SA-4(1)
Acquisition Process | Functional Properties of Controls. Require the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be implemented

Acquisition Process | Functional Properties of Controls. Require the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be implemented

Artefacts an auditor will ask for
  • Control descriptions
Where this commonly fails
  • Generic vendor docs
SA-4(10)
Use of Approved PIV Products

Employ only information technology products on FIPS 201-approved products list for PIV capability.

Artefacts an auditor will ask for
  • APL evidence
Where this commonly fails
  • Non-APL products
SA-4(2)
Acquisition Process | Design and Implementation Information for Controls. Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: [Selection (one or

Acquisition Process | Design and Implementation Information for Controls. Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: [Selection (one or

Artefacts an auditor will ask for
  • Design docs
Where this commonly fails
  • No design info
SA-4(5)
System, Component, and Service Configurations

Require developer to deliver system with security configurations preconfigured.

Artefacts an auditor will ask for
  • Secure defaults
Where this commonly fails
  • Insecure defaults
SA-4(9)
Acquisition Process | Functions, Ports, Protocols, and Services in Use. Require the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organizational use

Acquisition Process | Functions, Ports, Protocols, and Services in Use. Require the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organizational use

Artefacts an auditor will ask for
  • PPS list
Where this commonly fails
  • Undocumented PPS
SA-5
System Documentation

Obtain administrator and user documentation; protect; distribute to FedRAMP-defined personnel.

Artefacts an auditor will ask for
  • Control implementation statement for SA-5 citing the system mission and inheritance from common controls
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
Where this commonly fails
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
SA-8
Security and Privacy Engineering Principles

Apply FedRAMP-defined systems security and privacy engineering principles in development.

Artefacts an auditor will ask for
  • Control implementation statement for SA-8 citing the system mission and inheritance from common controls
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
  • Threat modelling performed inconsistently across product teams
SA-9
External System Services

Require providers of external system services to comply with security/privacy requirements; document oversight roles.

Artefacts an auditor will ask for
  • Control implementation statement for SA-9 citing the system mission and inheritance from common controls
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
SA-9(1)
External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and (b) Verify that the acquisition or outsourcing

External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and (b) Verify that the acquisition or outsourcing

Artefacts an auditor will ask for
  • Pre-acquisition RA
Where this commonly fails
  • No pre-procurement RA
SA-9(2)
Identification of Functions, Ports, Protocols, and Services

Require providers to identify functions, ports, protocols, services required for external services.

Artefacts an auditor will ask for
  • PPS documentation
Where this commonly fails
  • Undocumented
SA-9(5)
External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or

External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or

Artefacts an auditor will ask for
  • US-only attestation
Where this commonly fails
  • Foreign data residency

SC - System and Communications Protection

SC-1
Policy and Procedures

Develop and review system/comms protection policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for SC-1 citing the system mission and inheritance from common controls
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
SC-10
Network Disconnect

Terminate network connection at end of session or after FedRAMP-defined inactivity period (no longer than 30 minutes).

Artefacts an auditor will ask for
  • Control implementation statement for SC-10 citing the system mission and inheritance from common controls
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-12
Cryptographic Key Establishment and Management

Establish and manage cryptographic keys per FedRAMP requirements (FIPS-validated, key escrow/recovery as appropriate).

Artefacts an auditor will ask for
  • Control implementation statement for SC-12 citing the system mission and inheritance from common controls
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-12(1)
Availability

Maintain availability of information in event of loss of cryptographic keys via key escrow or recovery; HIGH only.

Artefacts an auditor will ask for
  • Key recovery procedure
Where this commonly fails
  • No escrow
SC-13
Cryptographic Protection

Implement FedRAMP-defined cryptographic uses and approved cryptography (FIPS 140 validated).

Artefacts an auditor will ask for
  • Control implementation statement for SC-13 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
SC-15
Collaborative Computing Devices and Applications

Prohibit remote activation of collaborative computing devices (cameras, mics) without explicit user indication; provide explicit notification.

Artefacts an auditor will ask for
  • Control implementation statement for SC-15 citing the system mission and inheritance from common controls
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
SC-17
Public Key Infrastructure Certificates

Issue public key certificates under FedRAMP-defined policy or obtain from approved service providers.

Artefacts an auditor will ask for
  • Control implementation statement for SC-17 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
SC-18
Mobile Code

Define acceptable and unacceptable mobile code; authorize use; monitor.

Artefacts an auditor will ask for
  • Mobile code policy
Where this commonly fails
  • No policy
SC-2
Separation of System and User Functionality

Separate user functionality from system management functionality.

Artefacts an auditor will ask for
  • Control implementation statement for SC-2 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-20
Secure Name/Address Resolution Service (Authoritative)

Provide artifacts for additional data origin authentication and integrity verification (DNSSEC) for child zones; FedRAMP requires DNSSEC.

Artefacts an auditor will ask for
  • Control implementation statement for SC-20 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-21
Secure Name/Address Resolution Service (Recursive or Caching Resolver)

Request and perform data origin authentication and data integrity verification on name/address resolution responses; DNSSEC validation.

Artefacts an auditor will ask for
  • Control implementation statement for SC-21 citing the system mission and inheritance from common controls
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-22
Architecture and Provisioning for Name/Address Resolution Service

Ensure DNS systems are fault-tolerant and implement role separation.

Artefacts an auditor will ask for
  • Control implementation statement for SC-22 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
SC-23
Session Authenticity

Protect authenticity of communications sessions.

Artefacts an auditor will ask for
  • Control implementation statement for SC-23 citing the system mission and inheritance from common controls
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-24
Fail in Known State

Fail to FedRAMP-defined known secure state for FedRAMP-defined failures; preserve FedRAMP-defined information in failure; HIGH only.

Artefacts an auditor will ask for
  • Failure mode docs
Where this commonly fails
  • Undefined failure state
SC-28
Protection of Information at Rest

Protect confidentiality and integrity of FedRAMP-defined information at rest.

Artefacts an auditor will ask for
  • Control implementation statement for SC-28 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
SC-28(1)
Cryptographic Protection

Implement cryptographic mechanisms to prevent unauthorized disclosure/modification of FedRAMP-defined information on FedRAMP-defined components; FIPS-validated.

Artefacts an auditor will ask for
  • At-rest encryption attestation
Where this commonly fails
  • Backups unencrypted
SC-3
Security Function Isolation

Isolate security functions from non-security functions; HIGH only.

Artefacts an auditor will ask for
  • Process isolation evidence
Where this commonly fails
  • No isolation
SC-39
Process Isolation

Maintain separate execution domain for each executing system process.

Artefacts an auditor will ask for
  • Control implementation statement for SC-39 citing the system mission and inheritance from common controls
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-4
Information in Shared System Resources

Prevent unauthorized and unintended information transfer via shared system resources.

Artefacts an auditor will ask for
  • Control implementation statement for SC-4 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-45
System Time Synchronization. Synchronize system clocks within and between systems and system components

System Time Synchronization. Synchronize system clocks within and between systems and system components

Artefacts an auditor will ask for
  • NTP topology
Where this commonly fails
  • Clock drift
SC-45(1)
System Time Synchronization | Synchronization with Authoritative Time Source. (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and (b) Synchronize the internal system clocks to the authoritative

System Time Synchronization | Synchronization with Authoritative Time Source. (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and (b) Synchronize the internal system clocks to the authoritative

Artefacts an auditor will ask for
  • NTP authoritative source
Where this commonly fails
  • Public NTP only
SC-5
Denial-of-Service Protection

Protect against or limit effects of DoS attacks using FedRAMP-defined safeguards.

Artefacts an auditor will ask for
  • Control implementation statement for SC-5 citing the system mission and inheritance from common controls
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-7
Boundary Protection

Monitor/control communications at external boundary and key internal boundaries; implement subnetworks for publicly accessible components.

Artefacts an auditor will ask for
  • Control implementation statement for SC-7 citing the system mission and inheritance from common controls
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-7(10)
Prevent Exfiltration

Prevent exfiltration of information; conduct exfiltration tests at FedRAMP-defined frequency; HIGH only.

Artefacts an auditor will ask for
  • DLP config
  • Exfil test
Where this commonly fails
  • No DLP
SC-7(12)
Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components]

Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components]

Artefacts an auditor will ask for
  • Host firewall config
Where this commonly fails
  • Host firewall off
SC-7(18)
Boundary Protection | Fail Secure. Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device

Boundary Protection | Fail Secure. Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device

Artefacts an auditor will ask for
  • Fail-closed config
Where this commonly fails
  • Fail open
SC-7(20)
Dynamic Isolation and Segregation

Provide capability to dynamically isolate FedRAMP-defined system components.

Artefacts an auditor will ask for
  • Quarantine playbook
Where this commonly fails
  • No quarantine capability
SC-7(21)
Isolation of System Components

Employ boundary protection mechanisms to separate FedRAMP-defined components supporting FedRAMP-defined missions; HIGH only.

Artefacts an auditor will ask for
  • Mission-based segmentation
Where this commonly fails
  • No mission segregation
SC-7(3)
Access Points

Limit number of external network connections to system; TIC-aligned.

Artefacts an auditor will ask for
  • TIC/managed connections
Where this commonly fails
  • Multiple uncontrolled gateways
SC-7(4)
External Telecommunications Services

Implement managed interface for each external telecommunications service; establish traffic flow policy; protect confidentiality and integrity; document exceptions; review at least annually.

Artefacts an auditor will ask for
  • Telecom interface inventory
Where this commonly fails
  • Unmanaged services
SC-7(5)
Deny by Default Allow by Exception

Deny network communications by default; allow by exception.

Artefacts an auditor will ask for
  • Default deny rule
Where this commonly fails
  • Permissive rules
SC-7(7)
Split Tunneling for Remote Devices

Prevent split tunneling for remote devices unless securely provisioned.

Artefacts an auditor will ask for
  • VPN client policy
Where this commonly fails
  • Split tunneling enabled
SC-7(8)
Route Traffic to Authenticated Proxy Servers

Route internal traffic to FedRAMP-defined external networks through authenticated proxies.

Artefacts an auditor will ask for
  • Proxy config
Where this commonly fails
  • Direct egress
SC-8
Transmission Confidentiality and Integrity

Protect confidentiality and integrity of transmitted information using cryptographic mechanisms.

Artefacts an auditor will ask for
  • Control implementation statement for SC-8 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
SC-8(1)
Cryptographic Protection

Implement FIPS-validated cryptographic mechanisms to prevent unauthorized disclosure and detect changes during transmission.

Artefacts an auditor will ask for
  • FIPS 140 cert numbers
  • TLS scan
Where this commonly fails
  • TLS 1.0/1.1 enabled

SI - System and Information Integrity

SI-1
Policy and Procedures

Develop and review system/information integrity policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for SI-1 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • Input validation handled inconsistently across microservices
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
SI-10
Information Input Validation

Check validity of FedRAMP-defined information inputs.

Artefacts an auditor will ask for
  • Control implementation statement for SI-10 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-11
Error Handling

Generate error messages providing necessary info without revealing sensitive info; reveal only to authorized.

Artefacts an auditor will ask for
  • Error handling review
Where this commonly fails
  • Stack traces exposed
SI-12
Information Management and Retention

Manage and retain information consistent with applicable laws, regulations, policies, standards.

Artefacts an auditor will ask for
  • Control implementation statement for SI-12 citing the system mission and inheritance from common controls
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
Where this commonly fails
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
SI-16
Memory Protection

Implement FedRAMP-defined safeguards to protect memory from unauthorized code execution (DEP, ASLR).

Artefacts an auditor will ask for
  • Control implementation statement for SI-16 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
  • Input validation handled inconsistently across microservices
SI-2
Flaw Remediation

Identify, report, and correct system flaws; remediate within FedRAMP-defined timeframes (HIGH critical 15d, high 30d).

Artefacts an auditor will ask for
  • Control implementation statement for SI-2 citing the system mission and inheritance from common controls
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
Where this commonly fails
  • Input validation handled inconsistently across microservices
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-2(2)
Automated Flaw Remediation Status

Determine status of flaw remediation via automated mechanisms at FedRAMP-defined frequency (at least monthly).

Artefacts an auditor will ask for
  • Patch status dashboard
Where this commonly fails
  • Manual reporting
SI-2(3)
Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined

Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined

Artefacts an auditor will ask for
  • MTTR metrics
Where this commonly fails
  • No MTTR tracking
SI-3
Malicious Code Protection

Implement signature-based and non-signature-based malicious code protection; configure to scan endpoints and entry/exit points.

Artefacts an auditor will ask for
  • Control implementation statement for SI-3 citing the system mission and inheritance from common controls
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-4
System Monitoring

Monitor system to detect attacks; identify unauthorized use; deploy monitoring devices at boundaries and key internal points.

Artefacts an auditor will ask for
  • Control implementation statement for SI-4 citing the system mission and inheritance from common controls
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
SI-4(1)
System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system

System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system

Artefacts an auditor will ask for
  • IDS architecture
Where this commonly fails
  • Siloed IDS
SI-4(10)
Visibility of Encrypted Communications

Provide capability to render visible information in encrypted communications traffic to FedRAMP-defined system monitoring tools.

Artefacts an auditor will ask for
  • TLS inspection config
Where this commonly fails
  • Encrypted blind spots
SI-4(11)
Analyze Communications Traffic Anomalies

Analyze outbound traffic for anomalies indicating exfiltration or compromise.

Artefacts an auditor will ask for
  • NDR/anomaly tool
Where this commonly fails
  • No baseline
SI-4(12)
Automated Organization-Generated Alerts

Alert FedRAMP-defined personnel using automated mechanisms when FedRAMP-defined events occur; HIGH only.

Artefacts an auditor will ask for
  • Auto-alerting config
Where this commonly fails
  • Manual alerts
SI-4(14)
Wireless Intrusion Detection

Employ wireless intrusion detection to identify rogue wireless devices and detect attack attempts; HIGH only.

Artefacts an auditor will ask for
  • WIDS deployment
Where this commonly fails
  • No WIDS
SI-4(16)
System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system

System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system

Artefacts an auditor will ask for
  • SIEM correlation
Where this commonly fails
  • Siloed monitoring
SI-4(18)
System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points

System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points

Artefacts an auditor will ask for
  • DNS tunneling detection
Where this commonly fails
  • No covert channel detection
SI-4(19)
Risk for Individuals

Implement FedRAMP-defined additional monitoring of individuals identified as posing increased risk; HIGH only.

Artefacts an auditor will ask for
  • Heightened monitoring SOP
Where this commonly fails
  • No risk-based monitoring
SI-4(2)
Automated Tools and Mechanisms for Real-Time Analysis

Employ automated tools to support near-real-time analysis of events.

Artefacts an auditor will ask for
  • SIEM correlation
Where this commonly fails
  • Batch analysis only
SI-4(20)
Privileged Users

Implement FedRAMP-defined additional monitoring of privileged users; HIGH only.

Artefacts an auditor will ask for
  • Privileged session recording
Where this commonly fails
  • No PAM recording
SI-4(22)
Unauthorized Network Services

Detect network services not authorized; audit or alert FedRAMP-defined personnel.

Artefacts an auditor will ask for
  • Port scan baseline
Where this commonly fails
  • No unauthorized service detection
SI-4(23)
System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms]

System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms]

Artefacts an auditor will ask for
  • EDR coverage
Where this commonly fails
  • EDR gaps
SI-4(4)
Inbound and Outbound Communications Traffic

Determine criteria for unusual or unauthorized activity; monitor inbound/outbound communications.

Artefacts an auditor will ask for
  • Egress monitoring
Where this commonly fails
  • No egress monitoring
SI-4(5)
System-Generated Alerts

Alert FedRAMP-defined personnel when indications of compromise/potential compromise occur.

Artefacts an auditor will ask for
  • Alert rules
  • On-call rotation
Where this commonly fails
  • No on-call
SI-5
Security Alerts, Advisories, and Directives

Receive alerts/advisories/directives from FedRAMP-defined external organizations (US-CERT, CISA); generate internal; disseminate.

Artefacts an auditor will ask for
  • Control implementation statement for SI-5 citing the system mission and inheritance from common controls
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-5(1)
Automated Alerts and Advisories

Broadcast security alerts and advisories throughout organization via automated mechanisms; HIGH only.

Artefacts an auditor will ask for
  • Distribution platform
Where this commonly fails
  • Manual broadcasts
SI-6
Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system

Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system

Artefacts an auditor will ask for
  • Function verification logs
Where this commonly fails
  • No verification
SI-7
Software, Firmware, and Information Integrity

Employ integrity verification tools to detect unauthorized changes to software, firmware, information; HIGH only.

Artefacts an auditor will ask for
  • Control implementation statement for SI-7 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
SI-7(1)
Integrity Checks

Perform integrity checks of software, firmware, information at FedRAMP-defined frequency or trigger events.

Artefacts an auditor will ask for
  • Integrity check schedule
Where this commonly fails
  • Infrequent checks
SI-7(15)
Software, Firmware, and Information Integrity | Code Authentication

Implement cryptographic mechanisms to authenticate FedRAMP-defined software or firmware components prior to installation.

Artefacts an auditor will ask for
  • List of components subject to cryptographic authentication
  • Pipeline or configuration step performing signature verification before install
  • Records of components rejected for failing authentication
Where this commonly fails
  • Verification applied to vendor packages but not to internally built artefacts
  • No record kept of verification failures
SI-7(2)
Automated Notifications of Integrity Violations

Employ automated tools to provide notification of integrity violations to FedRAMP-defined personnel; HIGH only.

Artefacts an auditor will ask for
  • FIM alerts
Where this commonly fails
  • No alerting
SI-7(5)
Automated Response to Integrity Violations

Automatically shut down, restart, or implement FedRAMP-defined safeguards when integrity violations discovered; HIGH only.

Artefacts an auditor will ask for
  • Auto-response config
Where this commonly fails
  • Manual response only
SI-7(7)
Integration of Detection and Response

Incorporate detection of FedRAMP-defined unauthorized changes into IR capability.

Artefacts an auditor will ask for
  • IR playbook for FIM
Where this commonly fails
  • FIM not in IR
SI-8
Spam Protection

Employ spam protection at entry/exit points; update spam protection mechanisms when new releases available.

Artefacts an auditor will ask for
  • Email gateway config
Where this commonly fails
  • No spam protection
SI-8(2)
Spam Protection | Automatic Updates. Automatically update spam protection mechanisms [Assignment: organization-defined frequency]

Spam Protection | Automatic Updates. Automatically update spam protection mechanisms [Assignment: organization-defined frequency]

Artefacts an auditor will ask for
  • Auto-update config
Where this commonly fails
  • Manual updates

SR - Supply Chain Risk Management

SR-1
Policy and Procedures (SR-1)

Develop, document, disseminate, and review supply chain risk management policy and procedures at defined frequency.

Artefacts an auditor will ask for
  • Control implementation statement for SR-1 citing the system mission and inheritance from common controls
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Vendor risk tier ratings static despite changes in service scope
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
SR-10
Inspection of Systems or Components (SR-10)

Inspect systems or components at defined frequency or upon indications of tampering to detect compromise.

Artefacts an auditor will ask for
  • Control implementation statement for SR-10 citing the system mission and inheritance from common controls
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-11
Component Authenticity (SR-11)

Implement anti-counterfeit policy and procedures to detect and prevent counterfeit components.

Artefacts an auditor will ask for
  • Control implementation statement for SR-11 citing the system mission and inheritance from common controls
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
SR-11(1)
Component Authenticity | Anti-counterfeit Training. Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware)

Component Authenticity | Anti-counterfeit Training. Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware)

Artefacts an auditor will ask for
  • Training curriculum
  • Training records
  • LMS records
Where this commonly fails
  • No role-based training
SR-11(2)
Component Authenticity | Configuration Control for Component Service and Repair. Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system

Component Authenticity | Configuration Control for Component Service and Repair. Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system

Artefacts an auditor will ask for
  • Repair handling procedure
  • Asset transit logs
  • Asset tracker
Where this commonly fails
  • No revalidation after repair
SR-12
Component Disposal (SR-12)

Dispose of data, documentation, tools, or system components using defined techniques and methods.

Artefacts an auditor will ask for
  • Control implementation statement for SR-12 citing the system mission and inheritance from common controls
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
Where this commonly fails
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
  • Vendor risk tier ratings static despite changes in service scope
SR-2
Supply Chain Risk Management Plan (SR-2)

Develop a C-SCRM plan for managing supply chain risks for systems, components, and services; review and update at defined frequency.

Artefacts an auditor will ask for
  • Control implementation statement for SR-2 citing the system mission and inheritance from common controls
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Vendor risk tier ratings static despite changes in service scope
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
SR-2(1)
Supply Chain Risk Management Plan | Establish SCRM Team. Establish a supply chain risk management team consisting of [Assignment: organization-defined personnel, roles, and responsibilities] to lead and support the following SCRM activities: [Assignment: organization-defined

Supply Chain Risk Management Plan | Establish SCRM Team. Establish a supply chain risk management team consisting of [Assignment: organization-defined personnel, roles, and responsibilities] to lead and support the following SCRM activities: [Assignment: organization-defined

Artefacts an auditor will ask for
  • Team charter
  • Roster
  • Meeting minutes
  • Collaboration site
Where this commonly fails
  • No legal or procurement reps
SR-3
Supply Chain Controls and Processes (SR-3)

Establish processes to identify, protect, detect, respond, and recover across the supply chain lifecycle.

Artefacts an auditor will ask for
  • Control implementation statement for SR-3 citing the system mission and inheritance from common controls
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-5
Acquisition Strategies, Tools, and Methods (SR-5)

Employ acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks.

Artefacts an auditor will ask for
  • Control implementation statement for SR-5 citing the system mission and inheritance from common controls
  • Supplier incident notification clauses and exercise records
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-6
Supplier Assessments and Reviews (SR-6)

Assess and review the supply chain risk posture of suppliers at defined frequency and after significant events.

Artefacts an auditor will ask for
  • Control implementation statement for SR-6 citing the system mission and inheritance from common controls
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
Where this commonly fails
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-8
Notification Agreements (SR-8)

Establish agreements with suppliers for notification of supply chain compromises and relevant changes.

Artefacts an auditor will ask for
  • Control implementation statement for SR-8 citing the system mission and inheritance from common controls
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-9
Tamper Resistance and Detection (SR-9)

Implement tamper resistance and detection for systems, components, and devices.

Artefacts an auditor will ask for
  • Tamper procedures
  • Inspection logs
  • Tamper-evident packaging
Where this commonly fails
  • No tamper seal verification
SR-9(1)
Multiple Stages of SDLC (SR-9(1))

Apply tamper resistance and detection at multiple stages of the system development lifecycle.

Artefacts an auditor will ask for
  • SDLC integration plan
  • Stage gate records
  • CI and CD controls
Where this commonly fails
  • Only physical, no build-time controls
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FedRAMP High framework page.