Skip to content

Evidence request lists

FedRAMP Moderate

Evidence request list. 323 controls, 323 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

AC - Access Control

AC-1
Policy and Procedures

Develop and disseminate access control policy and procedures; review at least annually (FedRAMP parameter); update following defined events.

Artefacts an auditor will ask for
  • Control implementation statement for AC-1 citing the system mission and inheritance from common controls
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
Where this commonly fails
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
AC-11
Device Lock

Prevent further access by initiating device lock after 15 minutes inactivity (FedRAMP) or upon user request.

Artefacts an auditor will ask for
  • Control implementation statement for AC-11 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-11(1)
Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image

Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image

Artefacts an auditor will ask for
  • Lock screen image configuration
  • Screenshots showing pattern-hiding
  • MDM payload
Where this commonly fails
  • Lock shows live data
  • Configuration drift
  • No screenshot evidence
AC-12
Session Termination

Automatically terminate user session after FedRAMP-defined conditions (idle timeout, trigger events).

Artefacts an auditor will ask for
  • Control implementation statement for AC-12 citing the system mission and inheritance from common controls
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-14
Permitted Actions Without Identification or Authentication

Identify and document actions allowed without identification or authentication.

Artefacts an auditor will ask for
  • Control implementation statement for AC-14 citing the system mission and inheritance from common controls
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-17
Remote Access

Establish usage restrictions, configuration requirements, and authorize remote access prior to allowing.

Artefacts an auditor will ask for
  • Control implementation statement for AC-17 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
AC-17(1)
Monitoring and Control

Employ automated mechanisms to monitor and control remote access.

Artefacts an auditor will ask for
  • VPN logs
  • Remote session monitoring
Where this commonly fails
  • No remote session logging
AC-17(2)
Protection of Confidentiality and Integrity Using Encryption

Implement cryptographic mechanisms to protect remote access sessions; FIPS-validated.

Artefacts an auditor will ask for
  • FIPS 140 module list
  • TLS config
Where this commonly fails
  • Non-FIPS ciphers enabled
AC-17(3)
Managed Access Control Points

Route remote accesses through FedRAMP-defined number of managed network access control points.

Artefacts an auditor will ask for
  • Network ingress diagram
  • TIC compliance
Where this commonly fails
  • Split tunneling allowed
AC-17(4)
Privileged Commands and Access

Authorize execution of privileged commands and access to security-relevant information via remote access only for defined needs.

Artefacts an auditor will ask for
  • Bastion logs
  • Approved command list
Where this commonly fails
  • No bastion enforcement
AC-18
Wireless Access

Establish configuration requirements, usage restrictions, authorize wireless access.

Artefacts an auditor will ask for
  • Control implementation statement for AC-18 citing the system mission and inheritance from common controls
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
AC-18(1)
Authentication and Encryption

Protect wireless access using authentication and encryption (WPA2/3 Enterprise minimum).

Artefacts an auditor will ask for
  • WPA3 config
  • RADIUS records
Where this commonly fails
  • PSK in use
AC-18(3)
Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment

Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment

Artefacts an auditor will ask for
  • MDM policy
Where this commonly fails
  • Bluetooth/Wi-Fi enabled by default
AC-19
Access Control for Mobile Devices

Establish configuration requirements and usage restrictions for mobile devices.

Artefacts an auditor will ask for
  • Control implementation statement for AC-19 citing the system mission and inheritance from common controls
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
AC-19(5)
Full Device or Container-Based Encryption

Employ full device or container-based encryption on mobile devices.

Artefacts an auditor will ask for
  • Encryption attestation
Where this commonly fails
  • Personal containers unencrypted
AC-2
Account Management

Manage accounts; review at least monthly for privileged, every six months for non-privileged (FedRAMP); notify within FedRAMP-defined timeframes on changes.

Artefacts an auditor will ask for
  • Control implementation statement for AC-2 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
AC-2(1)
Automated System Account Management

Support account management via automated mechanisms; required at HIGH baseline.

Artefacts an auditor will ask for
  • IDP configuration
  • Workflow automation evidence
  • SCIM provisioning logs
Where this commonly fails
  • Manual ticket-only provisioning
  • No automated deprovisioning
AC-2(12)
Account Monitoring for Atypical Usage

Monitor accounts for atypical use; report anomalies to defined personnel.

Artefacts an auditor will ask for
  • UEBA reports
  • Anomaly alerts
Where this commonly fails
  • No behavior baseline
AC-2(13)
Disable Accounts for High-Risk Individuals

Disable accounts of users posing significant risk within FedRAMP-defined timeframe (1 hour).

Artefacts an auditor will ask for
  • Insider threat workflow
  • 1-hour disable evidence
Where this commonly fails
  • No coordination with HR/legal
AC-2(2)
Automated Temporary and Emergency Account Management

Automatically disable temporary and emergency accounts within FedRAMP-defined timeframe (no longer than 24 hours).

Artefacts an auditor will ask for
  • Temp account expiry logs
  • Automation script
  • JIT access records
Where this commonly fails
  • No automated expiry
  • Emergency accounts persist
AC-2(3)
Disable Accounts

Disable accounts within FedRAMP-defined timeframe when no longer required, terminated, or inactive (35 days inactive).

Artefacts an auditor will ask for
  • Inactivity disable logs
  • HR-IAM integration
  • 35-day report
Where this commonly fails
  • Inactive accounts active over 35 days
AC-2(4)
Automated Audit Actions

Automatically audit account creation, modification, enabling, disabling, removal; notify defined personnel.

Artefacts an auditor will ask for
  • Account change audit logs
  • Alerting rules
Where this commonly fails
  • No alerts on account changes
AC-2(5)
Inactivity Logout

Require users to log out when inactivity exceeds FedRAMP-defined period (15 minutes for non-mobile, 30 for mobile).

Artefacts an auditor will ask for
  • Session timeout config
  • Policy baseline
Where this commonly fails
  • Timeout over 15 minutes
AC-2(7)
Privileged User Accounts

Establish and administer privileged accounts per role-based scheme; monitor role assignments; revoke when no longer needed.

Artefacts an auditor will ask for
  • Privileged role catalog
  • PAM logs
  • Revocation records
Where this commonly fails
  • Standing admin access
  • No PAM deployment
AC-2(9)
Restrictions on Use of Shared and Group Accounts

Only permit shared/group accounts when meeting FedRAMP-defined conditions; document and approve.

Artefacts an auditor will ask for
  • Shared account inventory
  • Approval records
Where this commonly fails
  • Shared accounts undocumented
AC-20
Use of External Systems

Establish terms and conditions for use of external systems; prohibit unless authorized.

Artefacts an auditor will ask for
  • Control implementation statement for AC-20 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-20(1)
Limits on Authorized Use

Permit use of external systems only after verifying security/privacy controls or approved connection agreement.

Artefacts an auditor will ask for
  • Interconnection agreements
  • Vendor assessments
Where this commonly fails
  • Missing ISA
AC-20(2)
Portable Storage Devices Restricted Use

Restrict use of organization-controlled portable storage on external systems.

Artefacts an auditor will ask for
  • USB control policy
  • DLP rules
Where this commonly fails
  • USB unrestricted
AC-21
Information Sharing

Enable authorized users to determine whether access authorizations match sharing restrictions.

Artefacts an auditor will ask for
  • Sharing policy
  • Classification labels
Where this commonly fails
  • No sharing review process
AC-22
Publicly Accessible Content

Designate users authorized to post; train them; review content quarterly for nonpublic information.

Artefacts an auditor will ask for
  • Control implementation statement for AC-22 citing the system mission and inheritance from common controls
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
AC-3
Access Enforcement

Enforce approved authorizations for logical access in accordance with policy.

Artefacts an auditor will ask for
  • Control implementation statement for AC-3 citing the system mission and inheritance from common controls
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
AC-4
Information Flow Enforcement

Enforce approved information flow control policies between connected systems and within the system.

Artefacts an auditor will ask for
  • Control implementation statement for AC-4 citing the system mission and inheritance from common controls
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-4(21)
Physical or Logical Separation of Information Flows

Separate information flows logically or physically using FedRAMP-defined mechanisms.

Artefacts an auditor will ask for
  • VLAN/VRF design
  • Tenant isolation evidence
Where this commonly fails
  • Shared broadcast domain
AC-5
Separation of Duties

Identify and document duties requiring separation; define access authorizations to support.

Artefacts an auditor will ask for
  • Control implementation statement for AC-5 citing the system mission and inheritance from common controls
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
AC-6
Least Privilege

Employ least privilege; allow only authorized access necessary to accomplish assigned tasks.

Artefacts an auditor will ask for
  • Control implementation statement for AC-6 citing the system mission and inheritance from common controls
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
AC-6(1)
Authorize Access to Security Functions

Authorize access for FedRAMP-defined personnel to security functions and security-relevant information.

Artefacts an auditor will ask for
  • Security admin role list
  • Approval records
Where this commonly fails
  • Undocumented sec-admin access
AC-6(10)
Prohibit Non-Privileged Users from Executing Privileged Functions

Prevent non-privileged users from executing privileged functions.

Artefacts an auditor will ask for
  • LPE prevention controls
  • EDR config
Where this commonly fails
  • Setuid binaries unaudited
AC-6(2)
Non-Privileged Access for Nonsecurity Functions

Require privileged users to use non-privileged accounts for nonsecurity functions.

Artefacts an auditor will ask for
  • Dual-account policy
  • Browse-as-user evidence
Where this commonly fails
  • Admins browse with admin
AC-6(5)
Privileged Accounts

Restrict privileged accounts to FedRAMP-defined personnel or roles.

Artefacts an auditor will ask for
  • Privileged role list
  • Quarterly review
Where this commonly fails
  • No periodic review
AC-6(7)
Review of User Privileges

Review privileges at least quarterly (FedRAMP) and reassign or remove as needed.

Artefacts an auditor will ask for
  • Quarterly privilege review
  • Remediation tickets
Where this commonly fails
  • Annual-only review
AC-6(9)
Log Use of Privileged Functions

Log execution of privileged functions.

Artefacts an auditor will ask for
  • Sudo logs
  • PAM session recording
Where this commonly fails
  • No PAM session logs
AC-7
Unsuccessful Logon Attempts

Enforce limit of 3 consecutive invalid logon attempts within 15 minutes (FedRAMP); lock for 30 min or until released.

Artefacts an auditor will ask for
  • Control implementation statement for AC-7 citing the system mission and inheritance from common controls
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-8
System Use Notification

Display approved system use notification/banner before granting access; FedRAMP requires specific language.

Artefacts an auditor will ask for
  • Login banner screenshot
  • Banner text
Where this commonly fails
  • Missing FedRAMP banner language

AT - Awareness and Training

AT-1
Policy and Procedures

Develop, disseminate, and review awareness and training policy and procedures at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for AT-1 citing the system mission and inheritance from common controls
  • Insider threat awareness briefing materials
  • Training records retained in the learning management system
  • Attestation records signed at onboarding and annually
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
Where this commonly fails
  • Contractors and third parties not enrolled in mandatory training
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
  • Training content not reviewed annually for current threat trends
AT-2
Literacy Training and Awareness

Provide security awareness training within FedRAMP-defined timeframe of onboarding, on system change, and at least annually thereafter.

Artefacts an auditor will ask for
  • Control implementation statement for AT-2 citing the system mission and inheritance from common controls
  • Training records retained in the learning management system
  • Attestation records signed at onboarding and annually
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
Where this commonly fails
  • Contractors and third parties not enrolled in mandatory training
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
AT-2(2)
Insider Threat

Include insider threat recognition and reporting in awareness training.

Artefacts an auditor will ask for
  • Insider threat module
Where this commonly fails
  • Module absent
AT-2(3)
Social Engineering and Mining

Include social engineering and social mining recognition in training.

Artefacts an auditor will ask for
  • Phishing simulation results
Where this commonly fails
  • No phishing tests
AT-3
Role-Based Training

Provide role-based security training to personnel with significant security responsibilities before authorizing access and annually.

Artefacts an auditor will ask for
  • Control implementation statement for AT-3 citing the system mission and inheritance from common controls
  • Attestation records signed at onboarding and annually
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
  • Phishing simulation results with click and reporting rates
  • Insider threat awareness briefing materials
Where this commonly fails
  • Contractors and third parties not enrolled in mandatory training
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
  • Training content not reviewed annually for current threat trends
AT-4
Training Records

Document and monitor security training; retain records for FedRAMP-defined period (5 years).

Artefacts an auditor will ask for
  • Control implementation statement for AT-4 citing the system mission and inheritance from common controls
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
  • Phishing simulation results with click and reporting rates
  • Insider threat awareness briefing materials
Where this commonly fails
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
  • Training content not reviewed annually for current threat trends

AU - Audit and Accountability

AU-1
Policy and Procedures

Develop and review audit/accountability policy annually.

Artefacts an auditor will ask for
  • Control implementation statement for AU-1 citing the system mission and inheritance from common controls
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
Where this commonly fails
  • Audit log retention shorter than the policy mandated period
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
AU-11
Audit Record Retention

Retain audit records for at least one year (FedRAMP minimum) with 90 days immediately accessible online.

Artefacts an auditor will ask for
  • Control implementation statement for AU-11 citing the system mission and inheritance from common controls
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-12
Audit Record Generation

Provide audit record generation capability on all system components specified in AU-2.

Artefacts an auditor will ask for
  • Control implementation statement for AU-12 citing the system mission and inheritance from common controls
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-2
Event Logging

Identify event types selected for logging including FedRAMP minimum list; review and update at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for AU-2 citing the system mission and inheritance from common controls
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Audit log retention shorter than the policy mandated period
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
AU-3
Content of Audit Records

Audit records must contain: type, when, where, source, outcome, identity associated.

Artefacts an auditor will ask for
  • Control implementation statement for AU-3 citing the system mission and inheritance from common controls
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
AU-3(1)
Additional Audit Information

Generate audit records containing FedRAMP-defined additional information (session, host, full text of executed commands).

Artefacts an auditor will ask for
  • Enriched log sample
Where this commonly fails
  • Command text not captured
AU-4
Audit Log Storage Capacity

Allocate audit log storage capacity to accommodate FedRAMP-defined retention period.

Artefacts an auditor will ask for
  • Control implementation statement for AU-4 citing the system mission and inheritance from common controls
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-5
Response to Audit Logging Process Failures

Alert defined personnel on audit failure within FedRAMP timeframe; take defined action (overwrite oldest, shutdown, stop processing).

Artefacts an auditor will ask for
  • Control implementation statement for AU-5 citing the system mission and inheritance from common controls
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
AU-6
Audit Record Review, Analysis, and Reporting

Review and analyze audit records at least weekly (FedRAMP); report findings to defined personnel.

Artefacts an auditor will ask for
  • Control implementation statement for AU-6 citing the system mission and inheritance from common controls
  • Log review procedures with assigned analyst owners
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
  • Audit log retention shorter than the policy mandated period
AU-6(1)
Automated Process Integration

Integrate audit review with automated mechanisms (SIEM).

Artefacts an auditor will ask for
  • SIEM screenshot
Where this commonly fails
  • No SIEM
AU-6(3)
Correlate Audit Record Repositories

Analyze and correlate audit records across different repositories.

Artefacts an auditor will ask for
  • SIEM correlation rules
Where this commonly fails
  • Siloed logs
AU-7
Audit Record Reduction and Report Generation

Provide capability for audit record reduction and on-demand report generation.

Artefacts an auditor will ask for
  • Control implementation statement for AU-7 citing the system mission and inheritance from common controls
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-7(1)
Automatic Processing

Process audit records for events of interest based on defined criteria.

Artefacts an auditor will ask for
  • SIEM use cases
Where this commonly fails
  • No detection rules
AU-8
Time Stamps

Use internal system clocks; record timestamps with FedRAMP-defined granularity (1 second), UTC or known offset.

Artefacts an auditor will ask for
  • Control implementation statement for AU-8 citing the system mission and inheritance from common controls
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
  • Audit log retention shorter than the policy mandated period
AU-9
Protection of Audit Information

Protect audit information and tools from unauthorized access, modification, deletion.

Artefacts an auditor will ask for
  • Control implementation statement for AU-9 citing the system mission and inheritance from common controls
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
  • Audit log retention shorter than the policy mandated period
AU-9(4)
Access by Subset of Privileged Users

Authorize access to audit functionality only to subset of privileged users.

Artefacts an auditor will ask for
  • SIEM role list
Where this commonly fails
  • All admins see all logs

CA - Assessment, Authorization, and Monitoring

CA-1
Policy and Procedures

Develop and review assessment/authorization policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for CA-1 citing the system mission and inheritance from common controls
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
Where this commonly fails
  • Authorization boundary description does not match the asset inventory
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
CA-2
Control Assessments

Assess controls annually (FedRAMP); third-party assessor (3PAO) required; produce SAR.

Artefacts an auditor will ask for
  • Control implementation statement for CA-2 citing the system mission and inheritance from common controls
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • Authorization boundary description does not match the asset inventory
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
CA-2(1)
Independent Assessors

Employ independent assessors; FedRAMP-accredited 3PAO required.

Artefacts an auditor will ask for
  • 3PAO accreditation
  • Independence statement
Where this commonly fails
  • Non-accredited assessor
CA-2(3)
Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]

Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]

Artefacts an auditor will ask for
  • Leverage decision memo
Where this commonly fails
  • No reciprocity documentation
CA-3
Information Exchange

Approve and manage exchange of information with external systems using ISA, MOU, contract; review annually.

Artefacts an auditor will ask for
  • Control implementation statement for CA-3 citing the system mission and inheritance from common controls
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
CA-5
Plan of Action and Milestones

Develop POAM; update at least monthly (FedRAMP); track remediation timelines (HIGH 30 days, MOD 90).

Artefacts an auditor will ask for
  • Control implementation statement for CA-5 citing the system mission and inheritance from common controls
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
Where this commonly fails
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
CA-6
Authorization

Senior official authorizes system; reauthorize every three years or upon significant change.

Artefacts an auditor will ask for
  • Control implementation statement for CA-6 citing the system mission and inheritance from common controls
  • Authorization to operate memorandum signed by the authorizing official
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
Where this commonly fails
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
  • Authorization boundary description does not match the asset inventory
CA-7
Continuous Monitoring

Establish continuous monitoring strategy with FedRAMP-defined metrics, monitoring frequencies, ongoing assessments.

Artefacts an auditor will ask for
  • Control implementation statement for CA-7 citing the system mission and inheritance from common controls
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
Where this commonly fails
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
CA-7(1)
Independent Assessment

Employ independent assessors for ongoing monitoring; FedRAMP 3PAO annual.

Artefacts an auditor will ask for
  • 3PAO ConMon engagement
Where this commonly fails
  • No independent ConMon
CA-7(4)
Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring

Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring

Artefacts an auditor will ask for
  • Risk monitoring procedure
  • Risk register
  • Change-driven re-assessments
Where this commonly fails
  • Risk monitoring siloed
  • No change triggers
  • Register stale
CA-8
Penetration Testing

Conduct penetration testing annually on FedRAMP-defined systems and components.

Artefacts an auditor will ask for
  • Control implementation statement for CA-8 citing the system mission and inheritance from common controls
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
  • Authorization boundary description does not match the asset inventory
CA-8(1)
Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components

Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components

Artefacts an auditor will ask for
  • Independent firm SOW
Where this commonly fails
  • Internal team only
CA-8(2)
Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]

Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]

Artefacts an auditor will ask for
  • Red team report
Where this commonly fails
  • No red team activity
CA-9
Internal System Connections

Authorize internal connections of components to system; document interface characteristics.

Artefacts an auditor will ask for
  • Control implementation statement for CA-9 citing the system mission and inheritance from common controls
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
  • Authorization boundary description does not match the asset inventory

CM - Configuration Management

CM-1
Policy and Procedures

Develop and review configuration management policy annually.

Artefacts an auditor will ask for
  • Control implementation statement for CM-1 citing the system mission and inheritance from common controls
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Asset inventory missing cloud workloads and ephemeral resources
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
CM-10
Software Usage Restrictions

Use software in accordance with contracts and copyright laws; track licenses; document peer-to-peer file sharing controls.

Artefacts an auditor will ask for
  • Control implementation statement for CM-10 citing the system mission and inheritance from common controls
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-11
User-Installed Software

Establish policies governing installation of software by users; enforce; monitor compliance.

Artefacts an auditor will ask for
  • Control implementation statement for CM-11 citing the system mission and inheritance from common controls
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
CM-12
Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is processed and stored; b. Identify and document the users who have access

Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is processed and stored; b. Identify and document the users who have access

Artefacts an auditor will ask for
  • Data location map
Where this commonly fails
  • No data inventory
CM-12(1)
Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational

Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational

Artefacts an auditor will ask for
  • DLP/discovery tool
Where this commonly fails
  • No data discovery
CM-2
Baseline Configuration

Develop and maintain baseline configurations; review and update annually (FedRAMP) and when required.

Artefacts an auditor will ask for
  • Control implementation statement for CM-2 citing the system mission and inheritance from common controls
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Asset inventory missing cloud workloads and ephemeral resources
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-2(2)
Automation Support for Accuracy and Currency

Maintain baseline currency via automated mechanisms.

Artefacts an auditor will ask for
  • CMDB auto-discovery
Where this commonly fails
  • Manual CMDB
CM-2(3)
Retention of Previous Configurations

Retain FedRAMP-defined number of previous baseline configurations (3) to support rollback.

Artefacts an auditor will ask for
  • Snapshot history
Where this commonly fails
  • No rollback capability
CM-2(7)
Configure Systems and Components for High-Risk Areas

Issue systems/devices with FedRAMP-defined security safeguards to individuals traveling to high-risk locations.

Artefacts an auditor will ask for
  • Travel laptop policy
Where this commonly fails
  • No travel device program
CM-3
Configuration Change Control

Determine, document, and approve changes; track, review, audit; CAB or equivalent; analyze security impact.

Artefacts an auditor will ask for
  • Control implementation statement for CM-3 citing the system mission and inheritance from common controls
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-3(2)
Testing, Validation, and Documentation of Changes

Test, validate, and document changes before implementing on operational system.

Artefacts an auditor will ask for
  • Test plan
  • Validation results
Where this commonly fails
  • No pre-prod testing
CM-3(4)
Security and Privacy Representatives

Require security and privacy representatives on change board for FedRAMP-defined configuration changes.

Artefacts an auditor will ask for
  • CAB roster
Where this commonly fails
  • No security on CAB
CM-4
Impact Analyses

Analyze changes to determine potential security/privacy impacts.

Artefacts an auditor will ask for
  • Control implementation statement for CM-4 citing the system mission and inheritance from common controls
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
CM-4(2)
Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements

Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements

Artefacts an auditor will ask for
  • Post-change verification reports
  • Control testing results
  • Tickets linking change to verification
Where this commonly fails
  • No post-change testing
  • Verification not documented
  • Controls drift after change
CM-5
Access Restrictions for Change

Define, document, approve, enforce physical and logical access restrictions for changes.

Artefacts an auditor will ask for
  • Control implementation statement for CM-5 citing the system mission and inheritance from common controls
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-5(1)
Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions

Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions

Artefacts an auditor will ask for
  • Deploy logs
Where this commonly fails
  • No deploy audit trail
CM-5(5)
Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment:

Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment:

Artefacts an auditor will ask for
  • Documented list of privileges that permit change to system components and system related information in the production or operational environment
  • Identification of the accounts and roles holding those privileges, extracted from the production environment itself
  • Configuration evidence that developers and other non-operational roles cannot change production components
  • User privilege review records at the defined frequency, showing privileges reviewed and reevaluated
  • Records of privileges removed or reduced as a result of a review
Where this commonly fails
  • Break glass and deployment service accounts excluded from the review, though they carry the strongest change privilege
  • Review confirms the list is unchanged rather than reevaluating whether each privilege is still justified
  • Change privilege limited in the application while underlying platform, container or infrastructure as code paths remain open
CM-6
Configuration Settings

Establish/document configuration settings using checklists; CIS/USGCB/DISA STIG when available; HIGH baseline.

Artefacts an auditor will ask for
  • Control implementation statement for CM-6 citing the system mission and inheritance from common controls
  • Configuration drift detection reports from the CMDB or tooling
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
  • Asset inventory missing cloud workloads and ephemeral resources
CM-6(1)
Automated Management, Application, and Verification

Manage, apply, and verify configuration settings via automated mechanisms; HIGH only.

Artefacts an auditor will ask for
  • IaC pipelines
  • Compliance scanner
Where this commonly fails
  • Manual config
CM-7
Least Functionality

Configure system to provide only essential capabilities; prohibit unnecessary functions, services, ports, protocols.

Artefacts an auditor will ask for
  • Control implementation statement for CM-7 citing the system mission and inheritance from common controls
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
CM-7(1)
Periodic Review

Review system functions, ports, protocols, services at least monthly (FedRAMP); disable as unnecessary.

Artefacts an auditor will ask for
  • Monthly review records
Where this commonly fails
  • Annual-only review
CM-7(2)
Prevent Program Execution

Prevent program execution according to FedRAMP-defined policies (rules of behavior).

Artefacts an auditor will ask for
  • App control policy
Where this commonly fails
  • No application control
CM-7(5)
Authorized Software Allow-by-Exception

Identify and maintain authorized software list; employ allowlist; review at least annually; HIGH requirement.

Artefacts an auditor will ask for
  • Allowlist policy
  • Annual review
Where this commonly fails
  • No allowlisting
CM-8
System Component Inventory

Develop and document inventory of system components; review and update at least monthly (FedRAMP).

Artefacts an auditor will ask for
  • Control implementation statement for CM-8 citing the system mission and inheritance from common controls
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
  • Asset inventory missing cloud workloads and ephemeral resources
CM-8(1)
Updates During Installation and Removal

Update inventory as part of component installations, removals, updates.

Artefacts an auditor will ask for
  • Installation workflow
Where this commonly fails
  • Manual inventory
CM-8(3)
Automated Unauthorized Component Detection

Employ automated mechanisms to detect unauthorized components at FedRAMP-defined frequency; HIGH only continuous.

Artefacts an auditor will ask for
  • NAC alerts
  • Rogue device reports
Where this commonly fails
  • No rogue detection
CM-9
Configuration Management Plan

Develop, document, implement configuration management plan addressing roles, processes, items under CM, identification scheme.

Artefacts an auditor will ask for
  • Control implementation statement for CM-9 citing the system mission and inheritance from common controls
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
  • Asset inventory missing cloud workloads and ephemeral resources

CP - Contingency Planning

CP-1
Policy and Procedures

Develop and review contingency planning policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for CP-1 citing the system mission and inheritance from common controls
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Backups taken but restore tests never performed end to end
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
CP-10
System Recovery and Reconstitution

Provide for recovery and reconstitution of system to known state within RTO.

Artefacts an auditor will ask for
  • Control implementation statement for CP-10 citing the system mission and inheritance from common controls
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-10(2)
System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based

System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based

Artefacts an auditor will ask for
  • DB transaction logs
Where this commonly fails
  • No transaction replay
CP-2
Contingency Plan

Develop contingency plan; review and update annually (FedRAMP); coordinate with related plans.

Artefacts an auditor will ask for
  • Control implementation statement for CP-2 citing the system mission and inheritance from common controls
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Backups taken but restore tests never performed end to end
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
CP-2(1)
Coordinate with Related Plans

Coordinate contingency plan with related plans (BCP, DRP, COOP, IRP).

Artefacts an auditor will ask for
  • Coordination matrix
Where this commonly fails
  • Siloed plans
CP-2(3)
Resume Mission and Business Functions

Plan for resumption of mission/business functions within FedRAMP-defined time period after contingency plan activation.

Artefacts an auditor will ask for
  • RTO documentation
Where this commonly fails
  • RTO undefined
CP-2(8)
Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions

Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions

Artefacts an auditor will ask for
  • BIA criticality map
Where this commonly fails
  • No criticality tiers
CP-3
Contingency Training

Provide contingency training to users assigned roles; within FedRAMP timeframe of role assignment and at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for CP-3 citing the system mission and inheritance from common controls
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
Where this commonly fails
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-4
Contingency Plan Testing

Test contingency plan at least annually (FedRAMP) using FedRAMP-defined tests; review test results.

Artefacts an auditor will ask for
  • Control implementation statement for CP-4 citing the system mission and inheritance from common controls
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
Where this commonly fails
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
CP-4(1)
Coordinate with Related Plans

Coordinate contingency plan testing with related plan testing.

Artefacts an auditor will ask for
  • Joint test plan
Where this commonly fails
  • Independent testing only
CP-6
Alternate Storage Site

Establish alternate storage site with agreements to permit storage and retrieval of system backup information.

Artefacts an auditor will ask for
  • Control implementation statement for CP-6 citing the system mission and inheritance from common controls
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
Where this commonly fails
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-6(1)
Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats

Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats

Artefacts an auditor will ask for
  • Geographic separation evidence
Where this commonly fails
  • Same metro zone
CP-6(3)
Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions

Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions

Artefacts an auditor will ask for
  • Accessibility analysis
Where this commonly fails
  • No analysis
CP-7
Alternate Processing Site

Establish alternate processing site with agreements for resumption of operations within FedRAMP-defined RTO.

Artefacts an auditor will ask for
  • Control implementation statement for CP-7 citing the system mission and inheritance from common controls
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
  • Backups taken but restore tests never performed end to end
CP-7(1)
Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats

Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats

Artefacts an auditor will ask for
  • Geographic separation
Where this commonly fails
  • Same region
CP-7(2)
Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions

Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions

Artefacts an auditor will ask for
  • Accessibility plan
Where this commonly fails
  • No plan
CP-7(3)
Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives)

Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives)

Artefacts an auditor will ask for
  • SLA priority clause
Where this commonly fails
  • No priority clauses
CP-8
Telecommunications Services

Establish alternate telecommunications services with agreements to permit resumption of system operations.

Artefacts an auditor will ask for
  • Control implementation statement for CP-8 citing the system mission and inheritance from common controls
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-8(1)
Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and (b) Request Telecommunications Service Priority

Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and (b) Request Telecommunications Service Priority

Artefacts an auditor will ask for
  • TSP enrollment
Where this commonly fails
  • No TSP
CP-8(2)
Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services

Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services

Artefacts an auditor will ask for
  • Diverse routing
Where this commonly fails
  • SPOFs unmitigated
CP-9
System Backup

Conduct backups of user-level, system-level, and security-related documentation; FedRAMP-defined frequency (daily incremental, weekly full).

Artefacts an auditor will ask for
  • Control implementation statement for CP-9 citing the system mission and inheritance from common controls
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
Where this commonly fails
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
  • Backups taken but restore tests never performed end to end
  • RTO and RPO targets undefined for tier two systems
CP-9(1)
Testing for Reliability and Integrity

Test backup information annually to verify reliability and integrity.

Artefacts an auditor will ask for
  • Restore test results
Where this commonly fails
  • Backups never restored
CP-9(8)
System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information]

System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information]

Artefacts an auditor will ask for
  • Backup encryption config
Where this commonly fails
  • Unencrypted backups

IA - Identification and Authentication

IA-1
Policy and Procedures

Develop and review identification and authentication policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for IA-1 citing the system mission and inheritance from common controls
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
Where this commonly fails
  • Default vendor credentials remain on appliances and IoT devices
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
IA-11
Re-Authentication

Require re-authentication when FedRAMP-defined circumstances occur (role change, privilege change, time period elapsed).

Artefacts an auditor will ask for
  • Control implementation statement for IA-11 citing the system mission and inheritance from common controls
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-12
Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a

Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a

Artefacts an auditor will ask for
  • Control implementation statement for IA-12 citing the system mission and inheritance from common controls
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-12(2)
Identity Proofing | Identity Evidence. Require evidence of individual identification be presented to the registration authority

Identity Proofing | Identity Evidence. Require evidence of individual identification be presented to the registration authority

Artefacts an auditor will ask for
  • Evidence collection records
Where this commonly fails
  • Weak proofing evidence
IA-12(3)
Identity Proofing | Identity Evidence Validation and Verification. Require that the presented identity evidence be validated and verified through [Assignment: organizational defined methods of validation and verification]

Identity Proofing | Identity Evidence Validation and Verification. Require that the presented identity evidence be validated and verified through [Assignment: organizational defined methods of validation and verification]

Artefacts an auditor will ask for
  • Validation procedure
Where this commonly fails
  • Self-attested only
IA-12(5)
Identity Proofing | Address Confirmation. Require that a [Selection: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address (physical or digital) of record

Identity Proofing | Address Confirmation. Require that a [Selection: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address (physical or digital) of record

Artefacts an auditor will ask for
  • Address confirmation records
Where this commonly fails
  • No address confirmation
IA-2
Identification and Authentication (Organizational Users)

Uniquely identify and authenticate organizational users and associate identity with processes acting on behalf of users.

Artefacts an auditor will ask for
  • Control implementation statement for IA-2 citing the system mission and inheritance from common controls
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Default vendor credentials remain on appliances and IoT devices
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
IA-2(1)
MFA to Privileged Accounts

Implement MFA for access to privileged accounts; phishing-resistant per FedRAMP.

Artefacts an auditor will ask for
  • FIDO2/PIV config
Where this commonly fails
  • SMS OTP only
IA-2(12)
Acceptance of PIV Credentials

Accept and electronically verify Personal Identity Verification credentials.

Artefacts an auditor will ask for
  • PIV reader config
Where this commonly fails
  • No PIV support
IA-2(2)
MFA to Non-Privileged Accounts

Implement MFA for non-privileged accounts; phishing-resistant per FedRAMP.

Artefacts an auditor will ask for
  • MFA coverage report
Where this commonly fails
  • Exemptions persist
IA-2(5)
Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources

Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources

Artefacts an auditor will ask for
  • Group account handling
Where this commonly fails
  • Direct group login
IA-2(6)
Identification and Authentication (organizational Users) | Access to Accounts , separate Device. Implement multi-factor authentication for [Selection (one or more): local; network; remote] access to [Selection (one or more): privileged accounts; non-privileged accounts] such that:

Identification and Authentication (organizational Users) | Access to Accounts , separate Device. Implement multi-factor authentication for [Selection (one or more): local; network; remote] access to [Selection (one or more): privileged accounts; non-privileged accounts] such that:

Artefacts an auditor will ask for
  • Hardware token policy
Where this commonly fails
  • Same-device push only
IA-2(8)
Access to Accounts Replay Resistant

Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.

Artefacts an auditor will ask for
  • Nonce/timestamp auth
Where this commonly fails
  • Replayable tokens
IA-3
Device Identification and Authentication

Uniquely identify and authenticate devices before establishing connection.

Artefacts an auditor will ask for
  • Control implementation statement for IA-3 citing the system mission and inheritance from common controls
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
IA-4
Identifier Management

Manage identifiers; uniquely identify; prevent reuse for FedRAMP-defined period.

Artefacts an auditor will ask for
  • Control implementation statement for IA-4 citing the system mission and inheritance from common controls
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-4(4)
Identifier Management | Identify User Status. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status]

Identifier Management | Identify User Status. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status]

Artefacts an auditor will ask for
  • Identifier schema
Where this commonly fails
  • No status markers
IA-5
Authenticator Management

Manage authenticators; verify identity prior to issuing; establish initial content; protect.

Artefacts an auditor will ask for
  • Control implementation statement for IA-5 citing the system mission and inheritance from common controls
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
IA-5(1)
Password-Based Authentication

Enforce password complexity per NIST SP 800-63B; minimum 12 characters (FedRAMP); compare against breach lists.

Artefacts an auditor will ask for
  • Password policy
  • Breach check integration
Where this commonly fails
  • No breach checking
IA-5(2)
Public Key-Based Authentication

Enforce authorized use of public key-based authentication; validate certificates; map identity to account.

Artefacts an auditor will ask for
  • PKI policy
  • CRL/OCSP config
Where this commonly fails
  • No revocation checking
IA-5(6)
Protection of Authenticators

Protect authenticators commensurate with security category of information they protect.

Artefacts an auditor will ask for
  • Authenticator handling SOP
Where this commonly fails
  • Tokens in cleartext
IA-5(7)
Authenticator Management | No Embedded Unencrypted Static Authenticators. Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage

Authenticator Management | No Embedded Unencrypted Static Authenticators. Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage

Artefacts an auditor will ask for
  • Secret scanning results
  • Vault adoption
Where this commonly fails
  • Hardcoded creds
IA-6
Authentication Feedback

Obscure authentication feedback during authentication process.

Artefacts an auditor will ask for
  • Control implementation statement for IA-6 citing the system mission and inheritance from common controls
  • Service account credential vault inventory and rotation logs
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
  • Default vendor credentials remain on appliances and IoT devices
IA-7
Cryptographic Module Authentication

Implement authentication to cryptographic modules meeting FIPS 140 (FedRAMP requires FIPS-validated).

Artefacts an auditor will ask for
  • Control implementation statement for IA-7 citing the system mission and inheritance from common controls
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-8
Identification and Authentication (Non-Organizational Users)

Uniquely identify and authenticate non-organizational users (e.g., federal customers).

Artefacts an auditor will ask for
  • Control implementation statement for IA-8 citing the system mission and inheritance from common controls
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
  • Default vendor credentials remain on appliances and IoT devices
IA-8(1)
Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies. Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies

Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies. Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies

Artefacts an auditor will ask for
  • Cross-agency PIV trust
Where this commonly fails
  • Internal PIV only
IA-8(2)
Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators. (a) Accept only external authenticators that are NIST-compliant; and (b) Document and maintain a list of accepted external authenticators

Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators. (a) Accept only external authenticators that are NIST-compliant; and (b) Document and maintain a list of accepted external authenticators

Artefacts an auditor will ask for
  • FICAM-approved IDP list
Where this commonly fails
  • Non-FICAM IDP
IA-8(4)
Identification and Authentication (non-organizational Users) | Use of Defined Profiles. Conform to the following profiles for identity management [Assignment: organization-defined identity management profiles]

Identification and Authentication (non-organizational Users) | Use of Defined Profiles. Conform to the following profiles for identity management [Assignment: organization-defined identity management profiles]

Artefacts an auditor will ask for
  • Profile documentation
Where this commonly fails
  • No profile mapping

IR - Incident Response

IR-1
Policy and Procedures

Requires an incident response policy and supporting procedures to be developed, documented, disseminated, reviewed and updated on a defined cycle.

Artefacts an auditor will ask for
  • Control implementation statement for IR-1 citing the system mission and inheritance from common controls
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Third party incident responder retainer expired
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-2
Incident Response Training

Requires incident response training for system users consistent with their assigned roles, within a defined period of assuming the role and periodically thereafter.

Artefacts an auditor will ask for
  • Control implementation statement for IR-2 citing the system mission and inheritance from common controls
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Third party incident responder retainer expired
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
IR-3
Incident Response Testing

Requires the incident response capability to be tested at a defined frequency using defined tests, to determine its effectiveness, and the results documented.

Artefacts an auditor will ask for
  • Control implementation statement for IR-3 citing the system mission and inheritance from common controls
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
Where this commonly fails
  • Third party incident responder retainer expired
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-3(2)
Incident Response Testing | Coordination with Related Plans. Coordinate incident response testing with organizational elements responsible for related plans

Incident Response Testing | Coordination with Related Plans. Coordinate incident response testing with organizational elements responsible for related plans

Artefacts an auditor will ask for
  • Joint test plan
Where this commonly fails
  • Isolated tests
IR-4
Incident Handling

Implement IR capability for preparation, detection/analysis, containment, eradication, recovery.

Artefacts an auditor will ask for
  • Control implementation statement for IR-4 citing the system mission and inheritance from common controls
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
Where this commonly fails
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-4(1)
Automated Incident Handling Processes

Support incident handling via automated mechanisms.

Artefacts an auditor will ask for
  • SOAR playbooks
Where this commonly fails
  • Manual-only handling
IR-5
Incident Monitoring

Track and document incidents.

Artefacts an auditor will ask for
  • Control implementation statement for IR-5 citing the system mission and inheritance from common controls
  • Incident response team roster with on call rotation
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
Where this commonly fails
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
  • Notification timelines miss jurisdictional regulatory deadlines
IR-6
Incident Reporting

Require personnel to report incidents to organizational authorities within FedRAMP timeframe; report to FedRAMP PMO and US-CERT.

Artefacts an auditor will ask for
  • Control implementation statement for IR-6 citing the system mission and inheritance from common controls
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
Where this commonly fails
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-6(1)
Automated Reporting

Report incidents via automated mechanisms.

Artefacts an auditor will ask for
  • Automated reporting workflow
Where this commonly fails
  • Manual email reports
IR-6(3)
Incident Reporting | Supply Chain Coordination. Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components

Incident Reporting | Supply Chain Coordination. Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components

Artefacts an auditor will ask for
  • Supplier notification log
Where this commonly fails
  • No supplier coordination
IR-7
Incident Response Assistance

Provide IR support resource (help desk, support group) for incident handling assistance.

Artefacts an auditor will ask for
  • Control implementation statement for IR-7 citing the system mission and inheritance from common controls
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
  • Notification timelines miss jurisdictional regulatory deadlines
  • Third party incident responder retainer expired
IR-7(1)
Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms]

Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms]

Artefacts an auditor will ask for
  • Knowledge base
Where this commonly fails
  • No automated KB
IR-8
Incident Response Plan

Develop and implement IRP; review and update annually; distribute.

Artefacts an auditor will ask for
  • Control implementation statement for IR-8 citing the system mission and inheritance from common controls
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
  • Notification timelines miss jurisdictional regulatory deadlines
IR-9
Information Spillage Response. Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to information spills; b. Identifying the specific information involved in the system contamination; c. Alerting

Information Spillage Response. Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to information spills; b. Identifying the specific information involved in the system contamination; c. Alerting

Artefacts an auditor will ask for
  • Spill response procedure
Where this commonly fails
  • No spill procedure
IR-9(2)
Information Spillage Response | Training. Provide information spillage response training [Assignment: organization-defined frequency]

Information Spillage Response | Training. Provide information spillage response training [Assignment: organization-defined frequency]

Artefacts an auditor will ask for
  • Spill training records
Where this commonly fails
  • No spill training
IR-9(3)
Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks while contaminated systems are undergoing corrective actions: [Assignment:

Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks while contaminated systems are undergoing corrective actions: [Assignment:

Artefacts an auditor will ask for
  • Post-spill procedure
Where this commonly fails
  • Personnel locked out
IR-9(4)
Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls]

Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls]

Artefacts an auditor will ask for
  • Exposure handling SOP
Where this commonly fails
  • No safeguards

MA - Maintenance

MA-1
Policy and Procedures

Develop and review maintenance policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for MA-1 citing the system mission and inheritance from common controls
  • Maintenance personnel access list with background check status
  • Remote maintenance session logs with MFA and supervision evidence
  • Tool sanitisation records for media leaving the facility
  • Vendor maintenance agreements with security clauses
Where this commonly fails
  • Emergency maintenance performed without retrospective documentation
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
MA-2
Controlled Maintenance

Schedule, document, review records of maintenance, repair, replacement of components.

Artefacts an auditor will ask for
  • Control implementation statement for MA-2 citing the system mission and inheritance from common controls
  • Remote maintenance session logs with MFA and supervision evidence
  • Tool sanitisation records for media leaving the facility
  • Vendor maintenance agreements with security clauses
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
Where this commonly fails
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
  • Maintenance tools not sanitised before removal from secure areas
MA-3
Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]

Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]

Artefacts an auditor will ask for
  • Control implementation statement for MA-3 citing the system mission and inheritance from common controls
  • Tool sanitisation records for media leaving the facility
  • Vendor maintenance agreements with security clauses
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
Where this commonly fails
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
MA-3(1)
Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications

Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications

Artefacts an auditor will ask for
  • Tool inspection records
Where this commonly fails
  • No inspections
MA-3(2)
Maintenance Tools | Inspect Media. Check media containing diagnostic and test programs for malicious code before the media are used in the system

Maintenance Tools | Inspect Media. Check media containing diagnostic and test programs for malicious code before the media are used in the system

Artefacts an auditor will ask for
  • Media scan logs
Where this commonly fails
  • No media scanning
MA-3(3)
Maintenance Tools | Prevent Unauthorized Removal. Prevent the removal of maintenance equipment containing organizational information by: (a) Verifying that there is no organizational information contained on the equipment; (b) Sanitizing or destroying the equipment;

Maintenance Tools | Prevent Unauthorized Removal. Prevent the removal of maintenance equipment containing organizational information by: (a) Verifying that there is no organizational information contained on the equipment; (b) Sanitizing or destroying the equipment;

Artefacts an auditor will ask for
  • Removal procedure
Where this commonly fails
  • No removal control
MA-4
Nonlocal Maintenance

Approve and monitor nonlocal maintenance activities; use strong authentication.

Artefacts an auditor will ask for
  • Control implementation statement for MA-4 citing the system mission and inheritance from common controls
  • Vendor maintenance agreements with security clauses
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
  • Maintenance personnel access list with background check status
  • Remote maintenance session logs with MFA and supervision evidence
Where this commonly fails
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
  • Maintenance tools not sanitised before removal from secure areas
MA-5
Maintenance Personnel

Establish process for authorizing maintenance personnel; maintain list of authorized personnel; supervise unauthorized.

Artefacts an auditor will ask for
  • Control implementation statement for MA-5 citing the system mission and inheritance from common controls
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
  • Maintenance personnel access list with background check status
  • Remote maintenance session logs with MFA and supervision evidence
Where this commonly fails
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
  • Maintenance tools not sanitised before removal from secure areas
MA-5(1)
Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clearances or are not U.S. citizens, that include the following requirements: (1)

Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clearances or are not U.S. citizens, that include the following requirements: (1)

Artefacts an auditor will ask for
  • Escort procedure
Where this commonly fails
  • Unescorted vendors
MA-6
Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure

Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure

Artefacts an auditor will ask for
  • Support contracts
Where this commonly fails
  • No SLA

MP - Media Protection

MP-1
Policy and Procedures

Develop and review media protection policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for MP-1 citing the system mission and inheritance from common controls
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
Where this commonly fails
  • Backup tapes shipped without tamper evident packaging
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
MP-2
Media Access

Restrict access to FedRAMP-defined types of digital and non-digital media to authorized personnel.

Artefacts an auditor will ask for
  • Control implementation statement for MP-2 citing the system mission and inheritance from common controls
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
Where this commonly fails
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
MP-3
Media Marking

Mark system media indicating distribution limitations, handling caveats, security markings.

Artefacts an auditor will ask for
  • Control implementation statement for MP-3 citing the system mission and inheritance from common controls
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
Where this commonly fails
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
MP-4
Media Storage

Physically control and securely store FedRAMP-defined types of media within FedRAMP-defined controlled areas.

Artefacts an auditor will ask for
  • Control implementation statement for MP-4 citing the system mission and inheritance from common controls
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
Where this commonly fails
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
MP-5
Media Transport

Protect and control media during transport outside controlled areas; maintain accountability; document activities; restrict transport to authorized personnel.

Artefacts an auditor will ask for
  • Control implementation statement for MP-5 citing the system mission and inheritance from common controls
  • Removable media usage policy and DLP enforcement evidence
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
Where this commonly fails
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
  • Backup tapes shipped without tamper evident packaging
MP-6
Media Sanitization

Sanitize media prior to disposal, release, or reuse using FedRAMP-defined methods (NIST SP 800-88).

Artefacts an auditor will ask for
  • Control implementation statement for MP-6 citing the system mission and inheritance from common controls
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
Where this commonly fails
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
MP-7
Media Use

Restrict or prohibit use of FedRAMP-defined types of media on FedRAMP-defined systems using safeguards.

Artefacts an auditor will ask for
  • Control implementation statement for MP-7 citing the system mission and inheritance from common controls
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
Where this commonly fails
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
  • Backup tapes shipped without tamper evident packaging

PE - Physical and Environmental Protection

PE-1
Policy and Procedures

Develop and review physical/environmental policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for PE-1 citing the system mission and inheritance from common controls
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Visitor logs incomplete or escort sign offs missing
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-10
Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system

Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system

Artefacts an auditor will ask for
  • Control implementation statement for PE-10 citing the system mission and inheritance from common controls
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-11
Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power

Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power

Artefacts an auditor will ask for
  • Control implementation statement for PE-11 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-12
Emergency Lighting

Employ and maintain automatic emergency lighting activating on power outage covering emergency exits.

Artefacts an auditor will ask for
  • Control implementation statement for PE-12 citing the system mission and inheritance from common controls
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-13
Fire Protection

Employ and maintain fire suppression and detection devices independent of energy source.

Artefacts an auditor will ask for
  • Control implementation statement for PE-13 citing the system mission and inheritance from common controls
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-13(1)
Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a

Fire Protection | Detection Systems. Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a

Artefacts an auditor will ask for
  • Alarm escalation
Where this commonly fails
  • No escalation list
PE-13(2)
Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an

Fire Protection | Suppression Systems. Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an

Artefacts an auditor will ask for
  • Automatic suppression
Where this commonly fails
  • Manual only
PE-14
Environmental Controls

Maintain temperature and humidity within FedRAMP-defined acceptable levels; monitor at FedRAMP frequency.

Artefacts an auditor will ask for
  • Control implementation statement for PE-14 citing the system mission and inheritance from common controls
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
  • Visitor logs incomplete or escort sign offs missing
PE-15
Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel

Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel

Artefacts an auditor will ask for
  • Control implementation statement for PE-15 citing the system mission and inheritance from common controls
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-16
Delivery and Removal

Authorize and control system components entering/exiting facility; maintain records.

Artefacts an auditor will ask for
  • Inventory in/out logs
Where this commonly fails
  • No records
PE-17
Alternate Work Site

Determine alternate work sites; employ FedRAMP-defined controls at alternate sites; assess effectiveness.

Artefacts an auditor will ask for
  • Control implementation statement for PE-17 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
  • Visitor logs incomplete or escort sign offs missing
PE-2
Physical Access Authorizations

Develop, approve, maintain list of individuals with authorized facility access; review at least quarterly (FedRAMP).

Artefacts an auditor will ask for
  • Control implementation statement for PE-2 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Visitor logs incomplete or escort sign offs missing
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
PE-3
Physical Access Control

Enforce physical access at entry/exit points; verify authorizations; control ingress/egress; maintain audit logs.

Artefacts an auditor will ask for
  • Control implementation statement for PE-3 citing the system mission and inheritance from common controls
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Visitor logs incomplete or escort sign offs missing
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-4
Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls]

Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls]

Artefacts an auditor will ask for
  • Control implementation statement for PE-4 citing the system mission and inheritance from common controls
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-5
Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output

Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output

Artefacts an auditor will ask for
  • Control implementation statement for PE-5 citing the system mission and inheritance from common controls
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-6
Monitoring Physical Access

Monitor physical access to facility; review access logs at least weekly (FedRAMP); coordinate review with IR.

Artefacts an auditor will ask for
  • Control implementation statement for PE-6 citing the system mission and inheritance from common controls
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-6(1)
Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment. Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment

Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment. Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment

Artefacts an auditor will ask for
  • CCTV deployment
Where this commonly fails
  • No surveillance
PE-8
Visitor Access Records

Maintain visitor access records for FedRAMP-defined period (1 year); review records monthly (FedRAMP).

Artefacts an auditor will ask for
  • Control implementation statement for PE-8 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-9
Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction

Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction

Artefacts an auditor will ask for
  • Control implementation statement for PE-9 citing the system mission and inheritance from common controls
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
  • Visitor logs incomplete or escort sign offs missing

PL - Planning

PL-1
Policy and Procedures

Develop and review planning policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for PL-1 citing the system mission and inheritance from common controls
  • Concept of operations describing system mission and data flows
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
Where this commonly fails
  • Planning artefacts lack version history and approval signatures
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
PL-10
Baseline Selection. Select a control baseline for the system

Baseline Selection. Select a control baseline for the system

Artefacts an auditor will ask for
  • Control implementation statement for PL-10 citing the system mission and inheritance from common controls
  • Concept of operations describing system mission and data flows
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
Where this commonly fails
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
PL-11
Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions

Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions

Artefacts an auditor will ask for
  • Control implementation statement for PL-11 citing the system mission and inheritance from common controls
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
Where this commonly fails
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
  • Architecture diagrams missing third party and SaaS dependencies
PL-2
System Security and Privacy Plans

Develop SSP that aligns with FedRAMP template; review and update annually.

Artefacts an auditor will ask for
  • Control implementation statement for PL-2 citing the system mission and inheritance from common controls
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
Where this commonly fails
  • Planning artefacts lack version history and approval signatures
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
PL-4
Rules of Behavior

Establish and provide rules describing user responsibilities; receive signed acknowledgement.

Artefacts an auditor will ask for
  • Control implementation statement for PL-4 citing the system mission and inheritance from common controls
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
  • Concept of operations describing system mission and data flows
  • Privacy and security integration documentation
Where this commonly fails
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
  • Architecture diagrams missing third party and SaaS dependencies
PL-4(1)
Rules of Behavior | Social Media and External Site/application Usage Restrictions. Include in the rules of behavior, restrictions on: (a) Use of social media, social networking sites, and external sites/applications; (b) Posting organizational information

Rules of Behavior | Social Media and External Site/application Usage Restrictions. Include in the rules of behavior, restrictions on: (a) Use of social media, social networking sites, and external sites/applications; (b) Posting organizational information

Artefacts an auditor will ask for
  • Social media clause
Where this commonly fails
  • Generic RoB
PL-8
Security and Privacy Architectures

Develop, document, maintain security/privacy architectures; review annually.

Artefacts an auditor will ask for
  • Control implementation statement for PL-8 citing the system mission and inheritance from common controls
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
Where this commonly fails
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
  • Architecture diagrams missing third party and SaaS dependencies
  • Planning artefacts lack version history and approval signatures

PS - Personnel Security

PS-1
Policy and Procedures

Develop and review personnel security policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for PS-1 citing the system mission and inheritance from common controls
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Background checks not re run when employees move to higher risk roles
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
PS-2
Position Risk Designation

Assign risk designation to positions; review and update at least every three years.

Artefacts an auditor will ask for
  • Control implementation statement for PS-2 citing the system mission and inheritance from common controls
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
PS-3
Personnel Screening

Screen individuals prior to authorizing access; rescreen at FedRAMP frequency per position risk; US citizenship may apply.

Artefacts an auditor will ask for
  • Control implementation statement for PS-3 citing the system mission and inheritance from common controls
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
Where this commonly fails
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
PS-3(3)
Personnel Screening | Information Requiring Special Protective Measures. Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection: (a) Have valid access authorizations that are demonstrated by assigned official government

Personnel Screening | Information Requiring Special Protective Measures. Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection: (a) Have valid access authorizations that are demonstrated by assigned official government

Artefacts an auditor will ask for
  • Special access agreements
Where this commonly fails
  • No special handling
PS-4
Personnel Termination

Disable access and revoke authenticators within FedRAMP-defined time (same day); conduct exit interview; retrieve property.

Artefacts an auditor will ask for
  • Control implementation statement for PS-4 citing the system mission and inheritance from common controls
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
Where this commonly fails
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
PS-5
Personnel Transfer

Review/confirm ongoing operational need for access when personnel transfer; modify access; notify within FedRAMP timeframe.

Artefacts an auditor will ask for
  • Control implementation statement for PS-5 citing the system mission and inheritance from common controls
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
Where this commonly fails
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
PS-6
Access Agreements

Develop access agreements; review and update annually; require signature before access.

Artefacts an auditor will ask for
  • Control implementation statement for PS-6 citing the system mission and inheritance from common controls
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
Where this commonly fails
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
PS-7
External Personnel Security

Establish personnel security requirements for external providers; require providers to notify within FedRAMP timeframe of personnel changes.

Artefacts an auditor will ask for
  • Control implementation statement for PS-7 citing the system mission and inheritance from common controls
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
PS-8
Personnel Sanctions

Employ formal sanctions for personnel failing to comply with security/privacy policies; notify defined personnel within FedRAMP timeframe.

Artefacts an auditor will ask for
  • Control implementation statement for PS-8 citing the system mission and inheritance from common controls
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
PS-9
Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions

Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions

Artefacts an auditor will ask for
  • Control implementation statement for PS-9 citing the system mission and inheritance from common controls
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
Where this commonly fails
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
  • Termination access removal exceeds documented SLA

RA - Risk Assessment

RA-1
Policy and Procedures

Develop and review risk assessment policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for RA-1 citing the system mission and inheritance from common controls
  • Risk register with likelihood, impact, and treatment owners
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
Where this commonly fails
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
RA-2
Security Categorization

Categorize system per FIPS 199; document; review and update annually.

Artefacts an auditor will ask for
  • Control implementation statement for RA-2 citing the system mission and inheritance from common controls
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
Where this commonly fails
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
RA-3
Risk Assessment

Conduct risk assessment annually (FedRAMP); document; review and update.

Artefacts an auditor will ask for
  • Control implementation statement for RA-3 citing the system mission and inheritance from common controls
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
  • Risk assessment methodology approved by leadership
  • Risk register with likelihood, impact, and treatment owners
Where this commonly fails
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
RA-3(1)
Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; and (b) Update the supply chain risk assessment [Assignment: organization-defined frequency], when

Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; and (b) Update the supply chain risk assessment [Assignment: organization-defined frequency], when

Artefacts an auditor will ask for
  • SCRM assessment
Where this commonly fails
  • No SCRM
RA-5
Vulnerability Monitoring and Scanning

Scan for vulnerabilities monthly (FedRAMP); OS/network weekly, web app monthly, database monthly; remediate within FedRAMP timeframes (HIGH critical 15d, high 30d).

Artefacts an auditor will ask for
  • Control implementation statement for RA-5 citing the system mission and inheritance from common controls
  • Risk acceptance memos signed by accountable executives
  • Risk assessment methodology approved by leadership
  • Risk register with likelihood, impact, and treatment owners
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
Where this commonly fails
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
RA-5(11)
Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components

Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components

Artefacts an auditor will ask for
  • VDP page
  • Triage SOP
Where this commonly fails
  • No VDP
RA-5(2)
Update Vulnerabilities to be Scanned

Update vulnerability list prior to scan, when new vulnerabilities identified, or at FedRAMP frequency.

Artefacts an auditor will ask for
  • Scanner update schedule
Where this commonly fails
  • Stale signatures
RA-5(3)
Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage

Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage

Artefacts an auditor will ask for
  • The documented definition of breadth and depth of vulnerability scanning coverage, stating which components and which vulnerability classes are in scope
  • Scanner configuration showing the target scope and the checks enabled, matched against that definition
  • Scan results demonstrating the defined breadth was actually reached, with an accounted list of assets not scanned
  • Reconciliation of scan targets against the system component inventory
  • Evidence of authenticated scanning where depth requires it, and the credentials scope used
Where this commonly fails
  • Breadth and depth asserted from the tool default rather than defined by the organisation, which is exactly what this enhancement requires
  • Scan coverage never reconciled against the asset inventory, so unscanned hosts are invisible
  • Unauthenticated scanning presented as satisfying depth, missing configuration and patch level findings
RA-5(5)
Privileged Access

Implement privileged access authorization to FedRAMP-defined components for vulnerability scanning.

Artefacts an auditor will ask for
  • Authenticated scan config
Where this commonly fails
  • Unauthenticated scans only
RA-9
Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or system services] at [Assignment: organization-defined decision points in the system development life cycle]

Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or system services] at [Assignment: organization-defined decision points in the system development life cycle]

Artefacts an auditor will ask for
  • Control implementation statement for RA-9 citing the system mission and inheritance from common controls
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
  • Risk assessment methodology approved by leadership
  • Risk register with likelihood, impact, and treatment owners
Where this commonly fails
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
  • Risk register entries lack named owner or due date
RA-7
Risk Response

Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so that identified risk is treated rather than only recorded.

Artefacts an auditor will ask for
  • risk response plan or POA&M showing decisions per finding
  • evidence findings from assessments and continuous monitoring feed the response process
  • records showing accepted risks are approved at the right level
Where this commonly fails
  • findings logged but never dispositioned
  • risk acceptance without documented authority
  • no link between monitoring output and response decisions

SA - System and Services Acquisition

SA-1
Policy and Procedures

Requires a system and services acquisition policy and supporting procedures to be developed, documented, disseminated, reviewed and updated on a defined cycle.

Artefacts an auditor will ask for
  • Control implementation statement for SA-1 citing the system mission and inheritance from common controls
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
Where this commonly fails
  • Security requirements absent from procurement templates for low value buys
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
SA-10
Developer Configuration Management

Require developer to perform CM during development, implementation, operation; document/track changes; implement only approved changes.

Artefacts an auditor will ask for
  • Control implementation statement for SA-10 citing the system mission and inheritance from common controls
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
Where this commonly fails
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
SA-11
Developer Testing and Evaluation

Require developer to test at FedRAMP-defined depth and coverage; document; correct flaws.

Artefacts an auditor will ask for
  • Control implementation statement for SA-11 citing the system mission and inheritance from common controls
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
SA-11(1)
Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of

Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of

Artefacts an auditor will ask for
  • SAST results
Where this commonly fails
  • No SAST
SA-11(2)
Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing

Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing

Artefacts an auditor will ask for
  • Threat models
Where this commonly fails
  • No threat modeling
SA-15
Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the

Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the

Artefacts an auditor will ask for
  • Control implementation statement for SA-15 citing the system mission and inheritance from common controls
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
Where this commonly fails
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
  • Threat modelling performed inconsistently across product teams
SA-15(3)
Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At the following decision points in the system development

Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At the following decision points in the system development

Artefacts an auditor will ask for
  • Contract or solicitation clause requiring the developer to perform criticality analysis
  • The developer's criticality analysis output identifying critical components and functions
  • Evidence the analysis was performed at the defined decision points in the development life cycle
  • Evidence the analysis was performed at the defined level of detail or decomposition
  • Organisational review of the developer's analysis and the actions taken on its findings
Where this commonly fails
  • Analysis delivered once at design with no repeat at the later decision points the requirement names
  • Decomposition stopped at the subsystem level, so the critical component inside it is never identified
  • Developer output accepted with no organisational review, so criticality findings drive no acquisition decision
SA-2
Allocation of Resources

Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning; determine, document and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process; and establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.

Artefacts an auditor will ask for
  • Mission and business process planning documentation recording the high-level information security and privacy requirements determined for the system or system service
  • Capital planning and investment control submission or business case showing the resources determined, documented and allocated to protect the system or system service
  • Programming and budgeting documentation showing a discrete line item for information security and privacy
  • Approved budget or spend plan carrying that line item, with its approval record
  • System security and privacy plan section recording the allocated resources and the basis for the amount
  • Records of review of the allocation when requirements or the system change across the system development life cycle
Where this commonly fails
  • Security and privacy requirements determined after the acquisition decision rather than during mission and business process planning
  • Security funding absorbed into a general IT or infrastructure line, so no discrete information security and privacy item exists to evidence
  • Resources named in a plan but never traced through to an approved budget or capital planning submission
  • Privacy resourcing omitted while security resourcing is documented, although the control covers both
  • Line item established once at authorization and not maintained through sustainment and supply chain activity
SA-22
Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support

Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support

Artefacts an auditor will ask for
  • Control implementation statement for SA-22 citing the system mission and inheritance from common controls
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
Where this commonly fails
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
SA-3
System Development Life Cycle

Manage system using SDLC incorporating security/privacy considerations.

Artefacts an auditor will ask for
  • Control implementation statement for SA-3 citing the system mission and inheritance from common controls
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
SA-4
Acquisition Process

Include security/privacy requirements in contracts; FedRAMP-defined assurance requirements.

Artefacts an auditor will ask for
  • Control implementation statement for SA-4 citing the system mission and inheritance from common controls
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
Where this commonly fails
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
SA-4(1)
Acquisition Process | Functional Properties of Controls. Require the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be implemented

Acquisition Process | Functional Properties of Controls. Require the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be implemented

Artefacts an auditor will ask for
  • Control descriptions
Where this commonly fails
  • Generic vendor docs
SA-4(10)
Use of Approved PIV Products

Employ only information technology products on FIPS 201-approved products list for PIV capability.

Artefacts an auditor will ask for
  • APL evidence
Where this commonly fails
  • Non-APL products
SA-4(2)
Acquisition Process | Design and Implementation Information for Controls. Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: [Selection (one or

Acquisition Process | Design and Implementation Information for Controls. Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: [Selection (one or

Artefacts an auditor will ask for
  • Design docs
Where this commonly fails
  • No design info
SA-4(9)
Acquisition Process | Functions, Ports, Protocols, and Services in Use. Require the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organizational use

Acquisition Process | Functions, Ports, Protocols, and Services in Use. Require the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organizational use

Artefacts an auditor will ask for
  • PPS list
Where this commonly fails
  • Undocumented PPS
SA-5
System Documentation

Obtain administrator and user documentation; protect; distribute to FedRAMP-defined personnel.

Artefacts an auditor will ask for
  • Control implementation statement for SA-5 citing the system mission and inheritance from common controls
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
Where this commonly fails
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
SA-8
Security and Privacy Engineering Principles

Apply FedRAMP-defined systems security and privacy engineering principles in development.

Artefacts an auditor will ask for
  • Control implementation statement for SA-8 citing the system mission and inheritance from common controls
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
  • Threat modelling performed inconsistently across product teams
SA-9
External System Services

Require providers of external system services to comply with security/privacy requirements; document oversight roles.

Artefacts an auditor will ask for
  • Control implementation statement for SA-9 citing the system mission and inheritance from common controls
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
SA-9(1)
External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and (b) Verify that the acquisition or outsourcing

External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and (b) Verify that the acquisition or outsourcing

Artefacts an auditor will ask for
  • Pre-acquisition RA
Where this commonly fails
  • No pre-procurement RA
SA-9(2)
Identification of Functions, Ports, Protocols, and Services

Require providers to identify functions, ports, protocols, services required for external services.

Artefacts an auditor will ask for
  • PPS documentation
Where this commonly fails
  • Undocumented
SA-9(5)
External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or

External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or

Artefacts an auditor will ask for
  • US-only attestation
Where this commonly fails
  • Foreign data residency

SC - System and Communications Protection

SC-1
Policy and Procedures

Develop and review system/comms protection policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for SC-1 citing the system mission and inheritance from common controls
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
SC-10
Network Disconnect

Terminate network connection at end of session or after FedRAMP-defined inactivity period (no longer than 30 minutes).

Artefacts an auditor will ask for
  • Control implementation statement for SC-10 citing the system mission and inheritance from common controls
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-12
Cryptographic Key Establishment and Management

Establish and manage cryptographic keys per FedRAMP requirements (FIPS-validated, key escrow/recovery as appropriate).

Artefacts an auditor will ask for
  • Control implementation statement for SC-12 citing the system mission and inheritance from common controls
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-13
Cryptographic Protection

Implement FedRAMP-defined cryptographic uses and approved cryptography (FIPS 140 validated).

Artefacts an auditor will ask for
  • Control implementation statement for SC-13 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
SC-15
Collaborative Computing Devices and Applications

Prohibit remote activation of collaborative computing devices (cameras, mics) without explicit user indication; provide explicit notification.

Artefacts an auditor will ask for
  • Control implementation statement for SC-15 citing the system mission and inheritance from common controls
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
SC-17
Public Key Infrastructure Certificates

Issue public key certificates under FedRAMP-defined policy or obtain from approved service providers.

Artefacts an auditor will ask for
  • Control implementation statement for SC-17 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
SC-18
Mobile Code

Define acceptable and unacceptable mobile code; authorize use; monitor.

Artefacts an auditor will ask for
  • Mobile code policy
Where this commonly fails
  • No policy
SC-2
Separation of System and User Functionality

Separate user functionality from system management functionality.

Artefacts an auditor will ask for
  • Control implementation statement for SC-2 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-20
Secure Name/Address Resolution Service (Authoritative)

Provide artifacts for additional data origin authentication and integrity verification (DNSSEC) for child zones; FedRAMP requires DNSSEC.

Artefacts an auditor will ask for
  • Control implementation statement for SC-20 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-21
Secure Name/Address Resolution Service (Recursive or Caching Resolver)

Request and perform data origin authentication and data integrity verification on name/address resolution responses; DNSSEC validation.

Artefacts an auditor will ask for
  • Control implementation statement for SC-21 citing the system mission and inheritance from common controls
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-22
Architecture and Provisioning for Name/Address Resolution Service

Ensure DNS systems are fault-tolerant and implement role separation.

Artefacts an auditor will ask for
  • Control implementation statement for SC-22 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
SC-23
Session Authenticity

Protect authenticity of communications sessions.

Artefacts an auditor will ask for
  • Control implementation statement for SC-23 citing the system mission and inheritance from common controls
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-28
Protection of Information at Rest

Protect confidentiality and integrity of FedRAMP-defined information at rest.

Artefacts an auditor will ask for
  • Control implementation statement for SC-28 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
SC-28(1)
Cryptographic Protection

Implement cryptographic mechanisms to prevent unauthorized disclosure/modification of FedRAMP-defined information on FedRAMP-defined components; FIPS-validated.

Artefacts an auditor will ask for
  • At-rest encryption attestation
Where this commonly fails
  • Backups unencrypted
SC-39
Process Isolation

Maintain separate execution domain for each executing system process.

Artefacts an auditor will ask for
  • Control implementation statement for SC-39 citing the system mission and inheritance from common controls
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-4
Information in Shared System Resources

Prevent unauthorized and unintended information transfer via shared system resources.

Artefacts an auditor will ask for
  • Control implementation statement for SC-4 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-45
System Time Synchronization. Synchronize system clocks within and between systems and system components

System Time Synchronization. Synchronize system clocks within and between systems and system components

Artefacts an auditor will ask for
  • NTP topology
Where this commonly fails
  • Clock drift
SC-45(1)
System Time Synchronization | Synchronization with Authoritative Time Source. (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and (b) Synchronize the internal system clocks to the authoritative

System Time Synchronization | Synchronization with Authoritative Time Source. (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and (b) Synchronize the internal system clocks to the authoritative

Artefacts an auditor will ask for
  • NTP authoritative source
Where this commonly fails
  • Public NTP only
SC-5
Denial-of-Service Protection

Protect against or limit effects of DoS attacks using FedRAMP-defined safeguards.

Artefacts an auditor will ask for
  • Control implementation statement for SC-5 citing the system mission and inheritance from common controls
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-7
Boundary Protection

Monitor/control communications at external boundary and key internal boundaries; implement subnetworks for publicly accessible components.

Artefacts an auditor will ask for
  • Control implementation statement for SC-7 citing the system mission and inheritance from common controls
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-7(12)
Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components]

Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components]

Artefacts an auditor will ask for
  • Host firewall config
Where this commonly fails
  • Host firewall off
SC-7(18)
Boundary Protection | Fail Secure. Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device

Boundary Protection | Fail Secure. Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device

Artefacts an auditor will ask for
  • Fail-closed config
Where this commonly fails
  • Fail open
SC-7(3)
Access Points

Limit number of external network connections to system; TIC-aligned.

Artefacts an auditor will ask for
  • TIC/managed connections
Where this commonly fails
  • Multiple uncontrolled gateways
SC-7(4)
External Telecommunications Services

Implement managed interface for each external telecommunications service; establish traffic flow policy; protect confidentiality and integrity; document exceptions; review at least annually.

Artefacts an auditor will ask for
  • Telecom interface inventory
Where this commonly fails
  • Unmanaged services
SC-7(5)
Deny by Default Allow by Exception

Deny network communications by default; allow by exception.

Artefacts an auditor will ask for
  • Default deny rule
Where this commonly fails
  • Permissive rules
SC-7(7)
Split Tunneling for Remote Devices

Prevent split tunneling for remote devices unless securely provisioned.

Artefacts an auditor will ask for
  • VPN client policy
Where this commonly fails
  • Split tunneling enabled
SC-7(8)
Route Traffic to Authenticated Proxy Servers

Route internal traffic to FedRAMP-defined external networks through authenticated proxies.

Artefacts an auditor will ask for
  • Proxy config
Where this commonly fails
  • Direct egress
SC-8
Transmission Confidentiality and Integrity

Protect confidentiality and integrity of transmitted information using cryptographic mechanisms.

Artefacts an auditor will ask for
  • Control implementation statement for SC-8 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
SC-8(1)
Cryptographic Protection

Implement FIPS-validated cryptographic mechanisms to prevent unauthorized disclosure and detect changes during transmission.

Artefacts an auditor will ask for
  • FIPS 140 cert numbers
  • TLS scan
Where this commonly fails
  • TLS 1.0/1.1 enabled

SI - System and Information Integrity

SI-1
Policy and Procedures

Develop and review system/information integrity policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for SI-1 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • Input validation handled inconsistently across microservices
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
SI-10
Information Input Validation

Check validity of FedRAMP-defined information inputs.

Artefacts an auditor will ask for
  • Control implementation statement for SI-10 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-11
Error Handling

Generate error messages providing necessary info without revealing sensitive info; reveal only to authorized.

Artefacts an auditor will ask for
  • Error handling review
Where this commonly fails
  • Stack traces exposed
SI-12
Information Management and Retention

Manage and retain information consistent with applicable laws, regulations, policies, standards.

Artefacts an auditor will ask for
  • Control implementation statement for SI-12 citing the system mission and inheritance from common controls
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
Where this commonly fails
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
SI-16
Memory Protection

Implement FedRAMP-defined safeguards to protect memory from unauthorized code execution (DEP, ASLR).

Artefacts an auditor will ask for
  • Control implementation statement for SI-16 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
  • Input validation handled inconsistently across microservices
SI-2
Flaw Remediation

Identify, report, and correct system flaws; remediate within FedRAMP-defined timeframes (HIGH critical 15d, high 30d).

Artefacts an auditor will ask for
  • Control implementation statement for SI-2 citing the system mission and inheritance from common controls
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
Where this commonly fails
  • Input validation handled inconsistently across microservices
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-2(2)
Automated Flaw Remediation Status

Determine status of flaw remediation via automated mechanisms at FedRAMP-defined frequency (at least monthly).

Artefacts an auditor will ask for
  • Patch status dashboard
Where this commonly fails
  • Manual reporting
SI-2(3)
Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined

Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined

Artefacts an auditor will ask for
  • MTTR metrics
Where this commonly fails
  • No MTTR tracking
SI-3
Malicious Code Protection

Implement signature-based and non-signature-based malicious code protection; configure to scan endpoints and entry/exit points.

Artefacts an auditor will ask for
  • Control implementation statement for SI-3 citing the system mission and inheritance from common controls
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-4
System Monitoring

Monitor system to detect attacks; identify unauthorized use; deploy monitoring devices at boundaries and key internal points.

Artefacts an auditor will ask for
  • Control implementation statement for SI-4 citing the system mission and inheritance from common controls
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
SI-4(1)
System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system

System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system

Artefacts an auditor will ask for
  • IDS architecture
Where this commonly fails
  • Siloed IDS
SI-4(16)
System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system

System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system

Artefacts an auditor will ask for
  • SIEM correlation
Where this commonly fails
  • Siloed monitoring
SI-4(18)
System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points

System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points

Artefacts an auditor will ask for
  • DNS tunneling detection
Where this commonly fails
  • No covert channel detection
SI-4(2)
Automated Tools and Mechanisms for Real-Time Analysis

Employ automated tools to support near-real-time analysis of events.

Artefacts an auditor will ask for
  • SIEM correlation
Where this commonly fails
  • Batch analysis only
SI-4(23)
System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms]

System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms]

Artefacts an auditor will ask for
  • EDR coverage
Where this commonly fails
  • EDR gaps
SI-4(4)
Inbound and Outbound Communications Traffic

Determine criteria for unusual or unauthorized activity; monitor inbound/outbound communications.

Artefacts an auditor will ask for
  • Egress monitoring
Where this commonly fails
  • No egress monitoring
SI-4(5)
System-Generated Alerts

Alert FedRAMP-defined personnel when indications of compromise/potential compromise occur.

Artefacts an auditor will ask for
  • Alert rules
  • On-call rotation
Where this commonly fails
  • No on-call
SI-5
Security Alerts, Advisories, and Directives

Receive alerts/advisories/directives from FedRAMP-defined external organizations (US-CERT, CISA); generate internal; disseminate.

Artefacts an auditor will ask for
  • Control implementation statement for SI-5 citing the system mission and inheritance from common controls
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-6
Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system

Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system

Artefacts an auditor will ask for
  • Function verification logs
Where this commonly fails
  • No verification
SI-7
Software, Firmware, and Information Integrity

Employ integrity verification tools to detect unauthorized changes to software, firmware, information; HIGH only.

Artefacts an auditor will ask for
  • Control implementation statement for SI-7 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
SI-7(1)
Integrity Checks

Perform integrity checks of software, firmware, information at FedRAMP-defined frequency or trigger events.

Artefacts an auditor will ask for
  • Integrity check schedule
Where this commonly fails
  • Infrequent checks
SI-7(7)
Integration of Detection and Response

Incorporate detection of FedRAMP-defined unauthorized changes into IR capability.

Artefacts an auditor will ask for
  • IR playbook for FIM
Where this commonly fails
  • FIM not in IR
SI-8
Spam Protection

Employ spam protection at entry/exit points; update spam protection mechanisms when new releases available.

Artefacts an auditor will ask for
  • Email gateway config
Where this commonly fails
  • No spam protection
SI-8(2)
Spam Protection | Automatic Updates. Automatically update spam protection mechanisms [Assignment: organization-defined frequency]

Spam Protection | Automatic Updates. Automatically update spam protection mechanisms [Assignment: organization-defined frequency]

Artefacts an auditor will ask for
  • Auto-update config
Where this commonly fails
  • Manual updates

SR - Supply Chain Risk Management

SR-1
Policy and Procedures (SR-1)

Develop, document, disseminate, and review supply chain risk management policy and procedures at defined frequency.

Artefacts an auditor will ask for
  • Control implementation statement for SR-1 citing the system mission and inheritance from common controls
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Vendor risk tier ratings static despite changes in service scope
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
SR-10
Inspection of Systems or Components (SR-10)

Inspect systems or components at defined frequency or upon indications of tampering to detect compromise.

Artefacts an auditor will ask for
  • Control implementation statement for SR-10 citing the system mission and inheritance from common controls
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-11
Component Authenticity (SR-11)

Implement anti-counterfeit policy and procedures to detect and prevent counterfeit components.

Artefacts an auditor will ask for
  • Control implementation statement for SR-11 citing the system mission and inheritance from common controls
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
SR-11(1)
Component Authenticity | Anti-counterfeit Training. Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware)

Component Authenticity | Anti-counterfeit Training. Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware)

Artefacts an auditor will ask for
  • Training curriculum
  • Training records
  • LMS records
Where this commonly fails
  • No role-based training
SR-11(2)
Component Authenticity | Configuration Control for Component Service and Repair. Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system

Component Authenticity | Configuration Control for Component Service and Repair. Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system

Artefacts an auditor will ask for
  • Repair handling procedure
  • Asset transit logs
  • Asset tracker
Where this commonly fails
  • No revalidation after repair
SR-12
Component Disposal (SR-12)

Dispose of data, documentation, tools, or system components using defined techniques and methods.

Artefacts an auditor will ask for
  • Control implementation statement for SR-12 citing the system mission and inheritance from common controls
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
Where this commonly fails
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
  • Vendor risk tier ratings static despite changes in service scope
SR-2
Supply Chain Risk Management Plan (SR-2)

Develop a C-SCRM plan for managing supply chain risks for systems, components, and services; review and update at defined frequency.

Artefacts an auditor will ask for
  • Control implementation statement for SR-2 citing the system mission and inheritance from common controls
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Vendor risk tier ratings static despite changes in service scope
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
SR-2(1)
Supply Chain Risk Management Plan | Establish SCRM Team. Establish a supply chain risk management team consisting of [Assignment: organization-defined personnel, roles, and responsibilities] to lead and support the following SCRM activities: [Assignment: organization-defined

Supply Chain Risk Management Plan | Establish SCRM Team. Establish a supply chain risk management team consisting of [Assignment: organization-defined personnel, roles, and responsibilities] to lead and support the following SCRM activities: [Assignment: organization-defined

Artefacts an auditor will ask for
  • Team charter
  • Roster
  • Meeting minutes
  • Collaboration site
Where this commonly fails
  • No legal or procurement reps
SR-3
Supply Chain Controls and Processes (SR-3)

Establish processes to identify, protect, detect, respond, and recover across the supply chain lifecycle.

Artefacts an auditor will ask for
  • Control implementation statement for SR-3 citing the system mission and inheritance from common controls
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-5
Acquisition Strategies, Tools, and Methods (SR-5)

Employ acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks.

Artefacts an auditor will ask for
  • Control implementation statement for SR-5 citing the system mission and inheritance from common controls
  • Supplier incident notification clauses and exercise records
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-6
Supplier Assessments and Reviews (SR-6)

Assess and review the supply chain risk posture of suppliers at defined frequency and after significant events.

Artefacts an auditor will ask for
  • Control implementation statement for SR-6 citing the system mission and inheritance from common controls
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
Where this commonly fails
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-8
Notification Agreements (SR-8)

Establish agreements with suppliers for notification of supply chain compromises and relevant changes.

Artefacts an auditor will ask for
  • Control implementation statement for SR-8 citing the system mission and inheritance from common controls
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FedRAMP Moderate framework page.