FedRAMP Moderate
Evidence request list. 323 controls, 323 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
AC - Access Control
Develop and disseminate access control policy and procedures; review at least annually (FedRAMP parameter); update following defined events.
- Control implementation statement for AC-1 citing the system mission and inheritance from common controls
- System access request forms with business justification
- Joiner mover leaver workflow evidence integrated with HR
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Stale accounts retained for terminated personnel beyond the 24 hour SLA
- Privileged accounts shared across administrators without individual accountability
- Access reviews performed but exceptions never remediated
Prevent further access by initiating device lock after 15 minutes inactivity (FedRAMP) or upon user request.
- Control implementation statement for AC-11 citing the system mission and inheritance from common controls
- Joiner mover leaver workflow evidence integrated with HR
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- Privileged accounts shared across administrators without individual accountability
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
- Service accounts excluded from periodic recertification
Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image
- Lock screen image configuration
- Screenshots showing pattern-hiding
- MDM payload
- Lock shows live data
- Configuration drift
- No screenshot evidence
Automatically terminate user session after FedRAMP-defined conditions (idle timeout, trigger events).
- Control implementation statement for AC-12 citing the system mission and inheritance from common controls
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
- Service accounts excluded from periodic recertification
Identify and document actions allowed without identification or authentication.
- Control implementation statement for AC-14 citing the system mission and inheritance from common controls
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- System access request forms with business justification
- Joiner mover leaver workflow evidence integrated with HR
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
- Service accounts excluded from periodic recertification
Establish usage restrictions, configuration requirements, and authorize remote access prior to allowing.
- Control implementation statement for AC-17 citing the system mission and inheritance from common controls
- Joiner mover leaver workflow evidence integrated with HR
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- Role definitions drift from documented matrix without change control
- Service accounts excluded from periodic recertification
- Stale accounts retained for terminated personnel beyond the 24 hour SLA
- Privileged accounts shared across administrators without individual accountability
Employ automated mechanisms to monitor and control remote access.
- VPN logs
- Remote session monitoring
- No remote session logging
Implement cryptographic mechanisms to protect remote access sessions; FIPS-validated.
- FIPS 140 module list
- TLS config
- Non-FIPS ciphers enabled
Route remote accesses through FedRAMP-defined number of managed network access control points.
- Network ingress diagram
- TIC compliance
- Split tunneling allowed
Authorize execution of privileged commands and access to security-relevant information via remote access only for defined needs.
- Bastion logs
- Approved command list
- No bastion enforcement
Establish configuration requirements, usage restrictions, authorize wireless access.
- Control implementation statement for AC-18 citing the system mission and inheritance from common controls
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- Service accounts excluded from periodic recertification
- Stale accounts retained for terminated personnel beyond the 24 hour SLA
- Privileged accounts shared across administrators without individual accountability
Protect wireless access using authentication and encryption (WPA2/3 Enterprise minimum).
- WPA3 config
- RADIUS records
- PSK in use
Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment
- MDM policy
- Bluetooth/Wi-Fi enabled by default
Establish configuration requirements and usage restrictions for mobile devices.
- Control implementation statement for AC-19 citing the system mission and inheritance from common controls
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- System access request forms with business justification
- Joiner mover leaver workflow evidence integrated with HR
- Service accounts excluded from periodic recertification
- Stale accounts retained for terminated personnel beyond the 24 hour SLA
- Privileged accounts shared across administrators without individual accountability
- Access reviews performed but exceptions never remediated
Employ full device or container-based encryption on mobile devices.
- Encryption attestation
- Personal containers unencrypted
Manage accounts; review at least monthly for privileged, every six months for non-privileged (FedRAMP); notify within FedRAMP-defined timeframes on changes.
- Control implementation statement for AC-2 citing the system mission and inheritance from common controls
- Joiner mover leaver workflow evidence integrated with HR
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- Stale accounts retained for terminated personnel beyond the 24 hour SLA
- Privileged accounts shared across administrators without individual accountability
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
Support account management via automated mechanisms; required at HIGH baseline.
- IDP configuration
- Workflow automation evidence
- SCIM provisioning logs
- Manual ticket-only provisioning
- No automated deprovisioning
Monitor accounts for atypical use; report anomalies to defined personnel.
- UEBA reports
- Anomaly alerts
- No behavior baseline
Disable accounts of users posing significant risk within FedRAMP-defined timeframe (1 hour).
- Insider threat workflow
- 1-hour disable evidence
- No coordination with HR/legal
Automatically disable temporary and emergency accounts within FedRAMP-defined timeframe (no longer than 24 hours).
- Temp account expiry logs
- Automation script
- JIT access records
- No automated expiry
- Emergency accounts persist
Disable accounts within FedRAMP-defined timeframe when no longer required, terminated, or inactive (35 days inactive).
- Inactivity disable logs
- HR-IAM integration
- 35-day report
- Inactive accounts active over 35 days
Automatically audit account creation, modification, enabling, disabling, removal; notify defined personnel.
- Account change audit logs
- Alerting rules
- No alerts on account changes
Require users to log out when inactivity exceeds FedRAMP-defined period (15 minutes for non-mobile, 30 for mobile).
- Session timeout config
- Policy baseline
- Timeout over 15 minutes
Establish and administer privileged accounts per role-based scheme; monitor role assignments; revoke when no longer needed.
- Privileged role catalog
- PAM logs
- Revocation records
- Standing admin access
- No PAM deployment
Only permit shared/group accounts when meeting FedRAMP-defined conditions; document and approve.
- Shared account inventory
- Approval records
- Shared accounts undocumented
Establish terms and conditions for use of external systems; prohibit unless authorized.
- Control implementation statement for AC-20 citing the system mission and inheritance from common controls
- Joiner mover leaver workflow evidence integrated with HR
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- Privileged accounts shared across administrators without individual accountability
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
- Service accounts excluded from periodic recertification
Permit use of external systems only after verifying security/privacy controls or approved connection agreement.
- Interconnection agreements
- Vendor assessments
- Missing ISA
Restrict use of organization-controlled portable storage on external systems.
- USB control policy
- DLP rules
- USB unrestricted
Enable authorized users to determine whether access authorizations match sharing restrictions.
- Sharing policy
- Classification labels
- No sharing review process
Designate users authorized to post; train them; review content quarterly for nonpublic information.
- Control implementation statement for AC-22 citing the system mission and inheritance from common controls
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- System access request forms with business justification
- Joiner mover leaver workflow evidence integrated with HR
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
- Service accounts excluded from periodic recertification
- Stale accounts retained for terminated personnel beyond the 24 hour SLA
Enforce approved authorizations for logical access in accordance with policy.
- Control implementation statement for AC-3 citing the system mission and inheritance from common controls
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- Privileged accounts shared across administrators without individual accountability
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
Enforce approved information flow control policies between connected systems and within the system.
- Control implementation statement for AC-4 citing the system mission and inheritance from common controls
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- System access request forms with business justification
- Joiner mover leaver workflow evidence integrated with HR
- Privileged accounts shared across administrators without individual accountability
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
- Service accounts excluded from periodic recertification
Separate information flows logically or physically using FedRAMP-defined mechanisms.
- VLAN/VRF design
- Tenant isolation evidence
- Shared broadcast domain
Identify and document duties requiring separation; define access authorizations to support.
- Control implementation statement for AC-5 citing the system mission and inheritance from common controls
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- System access request forms with business justification
- Joiner mover leaver workflow evidence integrated with HR
- Privileged accounts shared across administrators without individual accountability
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
Employ least privilege; allow only authorized access necessary to accomplish assigned tasks.
- Control implementation statement for AC-6 citing the system mission and inheritance from common controls
- Quarterly privileged access review attestations
- System access request forms with business justification
- Joiner mover leaver workflow evidence integrated with HR
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
- Service accounts excluded from periodic recertification
- Stale accounts retained for terminated personnel beyond the 24 hour SLA
Authorize access for FedRAMP-defined personnel to security functions and security-relevant information.
- Security admin role list
- Approval records
- Undocumented sec-admin access
Prevent non-privileged users from executing privileged functions.
- LPE prevention controls
- EDR config
- Setuid binaries unaudited
Require privileged users to use non-privileged accounts for nonsecurity functions.
- Dual-account policy
- Browse-as-user evidence
- Admins browse with admin
Restrict privileged accounts to FedRAMP-defined personnel or roles.
- Privileged role list
- Quarterly review
- No periodic review
Review privileges at least quarterly (FedRAMP) and reassign or remove as needed.
- Quarterly privilege review
- Remediation tickets
- Annual-only review
Log execution of privileged functions.
- Sudo logs
- PAM session recording
- No PAM session logs
Enforce limit of 3 consecutive invalid logon attempts within 15 minutes (FedRAMP); lock for 30 min or until released.
- Control implementation statement for AC-7 citing the system mission and inheritance from common controls
- System access request forms with business justification
- Joiner mover leaver workflow evidence integrated with HR
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
- Service accounts excluded from periodic recertification
Display approved system use notification/banner before granting access; FedRAMP requires specific language.
- Login banner screenshot
- Banner text
- Missing FedRAMP banner language
AT - Awareness and Training
Develop, disseminate, and review awareness and training policy and procedures at least annually.
- Control implementation statement for AT-1 citing the system mission and inheritance from common controls
- Insider threat awareness briefing materials
- Training records retained in the learning management system
- Attestation records signed at onboarding and annually
- Annual security awareness training curriculum and completion roster
- Role based training plan for privileged users and developers
- Contractors and third parties not enrolled in mandatory training
- Role based training not refreshed when job duties change
- Phishing failures not followed by remedial coaching
- Training content not reviewed annually for current threat trends
Provide security awareness training within FedRAMP-defined timeframe of onboarding, on system change, and at least annually thereafter.
- Control implementation statement for AT-2 citing the system mission and inheritance from common controls
- Training records retained in the learning management system
- Attestation records signed at onboarding and annually
- Annual security awareness training curriculum and completion roster
- Role based training plan for privileged users and developers
- Contractors and third parties not enrolled in mandatory training
- Role based training not refreshed when job duties change
- Phishing failures not followed by remedial coaching
Include insider threat recognition and reporting in awareness training.
- Insider threat module
- Module absent
Include social engineering and social mining recognition in training.
- Phishing simulation results
- No phishing tests
Provide role-based security training to personnel with significant security responsibilities before authorizing access and annually.
- Control implementation statement for AT-3 citing the system mission and inheritance from common controls
- Attestation records signed at onboarding and annually
- Annual security awareness training curriculum and completion roster
- Role based training plan for privileged users and developers
- Phishing simulation results with click and reporting rates
- Insider threat awareness briefing materials
- Contractors and third parties not enrolled in mandatory training
- Role based training not refreshed when job duties change
- Phishing failures not followed by remedial coaching
- Training content not reviewed annually for current threat trends
Document and monitor security training; retain records for FedRAMP-defined period (5 years).
- Control implementation statement for AT-4 citing the system mission and inheritance from common controls
- Annual security awareness training curriculum and completion roster
- Role based training plan for privileged users and developers
- Phishing simulation results with click and reporting rates
- Insider threat awareness briefing materials
- Role based training not refreshed when job duties change
- Phishing failures not followed by remedial coaching
- Training content not reviewed annually for current threat trends
AU - Audit and Accountability
Develop and review audit/accountability policy annually.
- Control implementation statement for AU-1 citing the system mission and inheritance from common controls
- Time synchronisation evidence across logging endpoints
- Audit log integrity controls including write once storage or hashing
- Audit and accountability policy with retention periods defined
- List of auditable events and log source inventory
- Audit log retention shorter than the policy mandated period
- Reviewers acknowledge alerts but do not document investigation outcomes
- Clock drift across hosts breaks event correlation
Retain audit records for at least one year (FedRAMP minimum) with 90 days immediately accessible online.
- Control implementation statement for AU-11 citing the system mission and inheritance from common controls
- Audit log integrity controls including write once storage or hashing
- Audit and accountability policy with retention periods defined
- List of auditable events and log source inventory
- SIEM ingestion configuration showing all in scope systems
- Log review procedures with assigned analyst owners
- Reviewers acknowledge alerts but do not document investigation outcomes
- Clock drift across hosts breaks event correlation
- Privileged user activity not isolated for independent review
- Critical log sources missing from the SIEM with no detection coverage
Provide audit record generation capability on all system components specified in AU-2.
- Control implementation statement for AU-12 citing the system mission and inheritance from common controls
- Audit and accountability policy with retention periods defined
- List of auditable events and log source inventory
- SIEM ingestion configuration showing all in scope systems
- Log review procedures with assigned analyst owners
- Clock drift across hosts breaks event correlation
- Privileged user activity not isolated for independent review
- Critical log sources missing from the SIEM with no detection coverage
Identify event types selected for logging including FedRAMP minimum list; review and update at least annually.
- Control implementation statement for AU-2 citing the system mission and inheritance from common controls
- Audit log integrity controls including write once storage or hashing
- Audit and accountability policy with retention periods defined
- List of auditable events and log source inventory
- SIEM ingestion configuration showing all in scope systems
- Log review procedures with assigned analyst owners
- Audit log retention shorter than the policy mandated period
- Reviewers acknowledge alerts but do not document investigation outcomes
- Clock drift across hosts breaks event correlation
- Privileged user activity not isolated for independent review
Audit records must contain: type, when, where, source, outcome, identity associated.
- Control implementation statement for AU-3 citing the system mission and inheritance from common controls
- Audit and accountability policy with retention periods defined
- List of auditable events and log source inventory
- SIEM ingestion configuration showing all in scope systems
- Log review procedures with assigned analyst owners
- Reviewers acknowledge alerts but do not document investigation outcomes
- Clock drift across hosts breaks event correlation
- Privileged user activity not isolated for independent review
Generate audit records containing FedRAMP-defined additional information (session, host, full text of executed commands).
- Enriched log sample
- Command text not captured
Allocate audit log storage capacity to accommodate FedRAMP-defined retention period.
- Control implementation statement for AU-4 citing the system mission and inheritance from common controls
- List of auditable events and log source inventory
- SIEM ingestion configuration showing all in scope systems
- Log review procedures with assigned analyst owners
- Time synchronisation evidence across logging endpoints
- Audit log integrity controls including write once storage or hashing
- Reviewers acknowledge alerts but do not document investigation outcomes
- Clock drift across hosts breaks event correlation
- Privileged user activity not isolated for independent review
- Critical log sources missing from the SIEM with no detection coverage
Alert defined personnel on audit failure within FedRAMP timeframe; take defined action (overwrite oldest, shutdown, stop processing).
- Control implementation statement for AU-5 citing the system mission and inheritance from common controls
- SIEM ingestion configuration showing all in scope systems
- Log review procedures with assigned analyst owners
- Time synchronisation evidence across logging endpoints
- Audit log integrity controls including write once storage or hashing
- Reviewers acknowledge alerts but do not document investigation outcomes
- Clock drift across hosts breaks event correlation
- Privileged user activity not isolated for independent review
Review and analyze audit records at least weekly (FedRAMP); report findings to defined personnel.
- Control implementation statement for AU-6 citing the system mission and inheritance from common controls
- Log review procedures with assigned analyst owners
- Time synchronisation evidence across logging endpoints
- Audit log integrity controls including write once storage or hashing
- Audit and accountability policy with retention periods defined
- List of auditable events and log source inventory
- Clock drift across hosts breaks event correlation
- Privileged user activity not isolated for independent review
- Critical log sources missing from the SIEM with no detection coverage
- Audit log retention shorter than the policy mandated period
Integrate audit review with automated mechanisms (SIEM).
- SIEM screenshot
- No SIEM
Analyze and correlate audit records across different repositories.
- SIEM correlation rules
- Siloed logs
Provide capability for audit record reduction and on-demand report generation.
- Control implementation statement for AU-7 citing the system mission and inheritance from common controls
- Time synchronisation evidence across logging endpoints
- Audit log integrity controls including write once storage or hashing
- Audit and accountability policy with retention periods defined
- List of auditable events and log source inventory
- Clock drift across hosts breaks event correlation
- Privileged user activity not isolated for independent review
- Critical log sources missing from the SIEM with no detection coverage
Process audit records for events of interest based on defined criteria.
- SIEM use cases
- No detection rules
Use internal system clocks; record timestamps with FedRAMP-defined granularity (1 second), UTC or known offset.
- Control implementation statement for AU-8 citing the system mission and inheritance from common controls
- Audit log integrity controls including write once storage or hashing
- Audit and accountability policy with retention periods defined
- List of auditable events and log source inventory
- SIEM ingestion configuration showing all in scope systems
- Log review procedures with assigned analyst owners
- Clock drift across hosts breaks event correlation
- Privileged user activity not isolated for independent review
- Critical log sources missing from the SIEM with no detection coverage
- Audit log retention shorter than the policy mandated period
Protect audit information and tools from unauthorized access, modification, deletion.
- Control implementation statement for AU-9 citing the system mission and inheritance from common controls
- Audit and accountability policy with retention periods defined
- List of auditable events and log source inventory
- SIEM ingestion configuration showing all in scope systems
- Log review procedures with assigned analyst owners
- Privileged user activity not isolated for independent review
- Critical log sources missing from the SIEM with no detection coverage
- Audit log retention shorter than the policy mandated period
Authorize access to audit functionality only to subset of privileged users.
- SIEM role list
- All admins see all logs
CA - Assessment, Authorization, and Monitoring
Develop and review assessment/authorization policy at least annually.
- Control implementation statement for CA-1 citing the system mission and inheritance from common controls
- Continuous monitoring strategy with metric definitions
- Independent assessor statement of independence
- System security plan covering the authorization boundary
- Control assessment report with tester names and dates
- Authorization boundary description does not match the asset inventory
- POAM items past due without justification or risk acceptance
- Continuous monitoring metrics collected but not reported to leadership
Assess controls annually (FedRAMP); third-party assessor (3PAO) required; produce SAR.
- Control implementation statement for CA-2 citing the system mission and inheritance from common controls
- Independent assessor statement of independence
- System security plan covering the authorization boundary
- Control assessment report with tester names and dates
- Plan of action and milestones tracking open findings
- Authorization to operate memorandum signed by the authorizing official
- Authorization boundary description does not match the asset inventory
- POAM items past due without justification or risk acceptance
- Continuous monitoring metrics collected but not reported to leadership
- Assessment scope omits inherited cloud provider controls
Employ independent assessors; FedRAMP-accredited 3PAO required.
- 3PAO accreditation
- Independence statement
- Non-accredited assessor
Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements]
- Leverage decision memo
- No reciprocity documentation
Approve and manage exchange of information with external systems using ISA, MOU, contract; review annually.
- Control implementation statement for CA-3 citing the system mission and inheritance from common controls
- System security plan covering the authorization boundary
- Control assessment report with tester names and dates
- Plan of action and milestones tracking open findings
- Authorization to operate memorandum signed by the authorizing official
- POAM items past due without justification or risk acceptance
- Continuous monitoring metrics collected but not reported to leadership
- Assessment scope omits inherited cloud provider controls
Develop POAM; update at least monthly (FedRAMP); track remediation timelines (HIGH 30 days, MOD 90).
- Control implementation statement for CA-5 citing the system mission and inheritance from common controls
- Plan of action and milestones tracking open findings
- Authorization to operate memorandum signed by the authorizing official
- Continuous monitoring strategy with metric definitions
- Independent assessor statement of independence
- POAM items past due without justification or risk acceptance
- Continuous monitoring metrics collected but not reported to leadership
- Assessment scope omits inherited cloud provider controls
Senior official authorizes system; reauthorize every three years or upon significant change.
- Control implementation statement for CA-6 citing the system mission and inheritance from common controls
- Authorization to operate memorandum signed by the authorizing official
- Continuous monitoring strategy with metric definitions
- Independent assessor statement of independence
- System security plan covering the authorization boundary
- Control assessment report with tester names and dates
- Continuous monitoring metrics collected but not reported to leadership
- Assessment scope omits inherited cloud provider controls
- Reauthorization scheduled past the policy required interval
- Authorization boundary description does not match the asset inventory
Establish continuous monitoring strategy with FedRAMP-defined metrics, monitoring frequencies, ongoing assessments.
- Control implementation statement for CA-7 citing the system mission and inheritance from common controls
- Continuous monitoring strategy with metric definitions
- Independent assessor statement of independence
- System security plan covering the authorization boundary
- Control assessment report with tester names and dates
- Continuous monitoring metrics collected but not reported to leadership
- Assessment scope omits inherited cloud provider controls
- Reauthorization scheduled past the policy required interval
Employ independent assessors for ongoing monitoring; FedRAMP 3PAO annual.
- 3PAO ConMon engagement
- No independent ConMon
Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring
- Risk monitoring procedure
- Risk register
- Change-driven re-assessments
- Risk monitoring siloed
- No change triggers
- Register stale
Conduct penetration testing annually on FedRAMP-defined systems and components.
- Control implementation statement for CA-8 citing the system mission and inheritance from common controls
- Independent assessor statement of independence
- System security plan covering the authorization boundary
- Control assessment report with tester names and dates
- Plan of action and milestones tracking open findings
- Authorization to operate memorandum signed by the authorizing official
- Continuous monitoring metrics collected but not reported to leadership
- Assessment scope omits inherited cloud provider controls
- Reauthorization scheduled past the policy required interval
- Authorization boundary description does not match the asset inventory
Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components
- Independent firm SOW
- Internal team only
Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises]
- Red team report
- No red team activity
Authorize internal connections of components to system; document interface characteristics.
- Control implementation statement for CA-9 citing the system mission and inheritance from common controls
- System security plan covering the authorization boundary
- Control assessment report with tester names and dates
- Plan of action and milestones tracking open findings
- Authorization to operate memorandum signed by the authorizing official
- Assessment scope omits inherited cloud provider controls
- Reauthorization scheduled past the policy required interval
- Authorization boundary description does not match the asset inventory
CM - Configuration Management
Develop and review configuration management policy annually.
- Control implementation statement for CM-1 citing the system mission and inheritance from common controls
- Software inventory generated from authoritative discovery tooling
- Emergency change records with retroactive approvals
- Configuration management policy and change control procedure
- Approved baseline configurations for each platform family
- Asset inventory missing cloud workloads and ephemeral resources
- Baselines exist on paper but production hosts drift without alerting
- Emergency changes bypass CAB and lack retrospective review
Use software in accordance with contracts and copyright laws; track licenses; document peer-to-peer file sharing controls.
- Control implementation statement for CM-10 citing the system mission and inheritance from common controls
- Software inventory generated from authoritative discovery tooling
- Emergency change records with retroactive approvals
- Configuration management policy and change control procedure
- Approved baseline configurations for each platform family
- Baselines exist on paper but production hosts drift without alerting
- Emergency changes bypass CAB and lack retrospective review
- Unauthorised software present on endpoints not flagged by tooling
Establish policies governing installation of software by users; enforce; monitor compliance.
- Control implementation statement for CM-11 citing the system mission and inheritance from common controls
- Emergency change records with retroactive approvals
- Configuration management policy and change control procedure
- Approved baseline configurations for each platform family
- Change advisory board minutes with risk assessments
- Configuration drift detection reports from the CMDB or tooling
- Baselines exist on paper but production hosts drift without alerting
- Emergency changes bypass CAB and lack retrospective review
- Unauthorised software present on endpoints not flagged by tooling
- Hardening benchmarks applied at build but not re evaluated annually
Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is processed and stored; b. Identify and document the users who have access
- Data location map
- No data inventory
Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational
- DLP/discovery tool
- No data discovery
Develop and maintain baseline configurations; review and update annually (FedRAMP) and when required.
- Control implementation statement for CM-2 citing the system mission and inheritance from common controls
- Emergency change records with retroactive approvals
- Configuration management policy and change control procedure
- Approved baseline configurations for each platform family
- Change advisory board minutes with risk assessments
- Configuration drift detection reports from the CMDB or tooling
- Asset inventory missing cloud workloads and ephemeral resources
- Baselines exist on paper but production hosts drift without alerting
- Emergency changes bypass CAB and lack retrospective review
- Unauthorised software present on endpoints not flagged by tooling
Maintain baseline currency via automated mechanisms.
- CMDB auto-discovery
- Manual CMDB
Retain FedRAMP-defined number of previous baseline configurations (3) to support rollback.
- Snapshot history
- No rollback capability
Issue systems/devices with FedRAMP-defined security safeguards to individuals traveling to high-risk locations.
- Travel laptop policy
- No travel device program
Determine, document, and approve changes; track, review, audit; CAB or equivalent; analyze security impact.
- Control implementation statement for CM-3 citing the system mission and inheritance from common controls
- Configuration management policy and change control procedure
- Approved baseline configurations for each platform family
- Change advisory board minutes with risk assessments
- Configuration drift detection reports from the CMDB or tooling
- Baselines exist on paper but production hosts drift without alerting
- Emergency changes bypass CAB and lack retrospective review
- Unauthorised software present on endpoints not flagged by tooling
Test, validate, and document changes before implementing on operational system.
- Test plan
- Validation results
- No pre-prod testing
Require security and privacy representatives on change board for FedRAMP-defined configuration changes.
- CAB roster
- No security on CAB
Analyze changes to determine potential security/privacy impacts.
- Control implementation statement for CM-4 citing the system mission and inheritance from common controls
- Approved baseline configurations for each platform family
- Change advisory board minutes with risk assessments
- Configuration drift detection reports from the CMDB or tooling
- Software inventory generated from authoritative discovery tooling
- Emergency change records with retroactive approvals
- Baselines exist on paper but production hosts drift without alerting
- Emergency changes bypass CAB and lack retrospective review
- Unauthorised software present on endpoints not flagged by tooling
- Hardening benchmarks applied at build but not re evaluated annually
Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements
- Post-change verification reports
- Control testing results
- Tickets linking change to verification
- No post-change testing
- Verification not documented
- Controls drift after change
Define, document, approve, enforce physical and logical access restrictions for changes.
- Control implementation statement for CM-5 citing the system mission and inheritance from common controls
- Change advisory board minutes with risk assessments
- Configuration drift detection reports from the CMDB or tooling
- Software inventory generated from authoritative discovery tooling
- Emergency change records with retroactive approvals
- Baselines exist on paper but production hosts drift without alerting
- Emergency changes bypass CAB and lack retrospective review
- Unauthorised software present on endpoints not flagged by tooling
Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions
- Deploy logs
- No deploy audit trail
Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment:
- Documented list of privileges that permit change to system components and system related information in the production or operational environment
- Identification of the accounts and roles holding those privileges, extracted from the production environment itself
- Configuration evidence that developers and other non-operational roles cannot change production components
- User privilege review records at the defined frequency, showing privileges reviewed and reevaluated
- Records of privileges removed or reduced as a result of a review
- Break glass and deployment service accounts excluded from the review, though they carry the strongest change privilege
- Review confirms the list is unchanged rather than reevaluating whether each privilege is still justified
- Change privilege limited in the application while underlying platform, container or infrastructure as code paths remain open
Establish/document configuration settings using checklists; CIS/USGCB/DISA STIG when available; HIGH baseline.
- Control implementation statement for CM-6 citing the system mission and inheritance from common controls
- Configuration drift detection reports from the CMDB or tooling
- Software inventory generated from authoritative discovery tooling
- Emergency change records with retroactive approvals
- Configuration management policy and change control procedure
- Approved baseline configurations for each platform family
- Emergency changes bypass CAB and lack retrospective review
- Unauthorised software present on endpoints not flagged by tooling
- Hardening benchmarks applied at build but not re evaluated annually
- Asset inventory missing cloud workloads and ephemeral resources
Manage, apply, and verify configuration settings via automated mechanisms; HIGH only.
- IaC pipelines
- Compliance scanner
- Manual config
Configure system to provide only essential capabilities; prohibit unnecessary functions, services, ports, protocols.
- Control implementation statement for CM-7 citing the system mission and inheritance from common controls
- Software inventory generated from authoritative discovery tooling
- Emergency change records with retroactive approvals
- Configuration management policy and change control procedure
- Approved baseline configurations for each platform family
- Emergency changes bypass CAB and lack retrospective review
- Unauthorised software present on endpoints not flagged by tooling
- Hardening benchmarks applied at build but not re evaluated annually
Review system functions, ports, protocols, services at least monthly (FedRAMP); disable as unnecessary.
- Monthly review records
- Annual-only review
Prevent program execution according to FedRAMP-defined policies (rules of behavior).
- App control policy
- No application control
Identify and maintain authorized software list; employ allowlist; review at least annually; HIGH requirement.
- Allowlist policy
- Annual review
- No allowlisting
Develop and document inventory of system components; review and update at least monthly (FedRAMP).
- Control implementation statement for CM-8 citing the system mission and inheritance from common controls
- Emergency change records with retroactive approvals
- Configuration management policy and change control procedure
- Approved baseline configurations for each platform family
- Change advisory board minutes with risk assessments
- Configuration drift detection reports from the CMDB or tooling
- Emergency changes bypass CAB and lack retrospective review
- Unauthorised software present on endpoints not flagged by tooling
- Hardening benchmarks applied at build but not re evaluated annually
- Asset inventory missing cloud workloads and ephemeral resources
Update inventory as part of component installations, removals, updates.
- Installation workflow
- Manual inventory
Employ automated mechanisms to detect unauthorized components at FedRAMP-defined frequency; HIGH only continuous.
- NAC alerts
- Rogue device reports
- No rogue detection
Develop, document, implement configuration management plan addressing roles, processes, items under CM, identification scheme.
- Control implementation statement for CM-9 citing the system mission and inheritance from common controls
- Configuration management policy and change control procedure
- Approved baseline configurations for each platform family
- Change advisory board minutes with risk assessments
- Configuration drift detection reports from the CMDB or tooling
- Unauthorised software present on endpoints not flagged by tooling
- Hardening benchmarks applied at build but not re evaluated annually
- Asset inventory missing cloud workloads and ephemeral resources
CP - Contingency Planning
Develop and review contingency planning policy at least annually.
- Control implementation statement for CP-1 citing the system mission and inheritance from common controls
- Backup schedule, retention, and offsite or immutable copy evidence
- Annual tabletop and full failover test reports
- Alternate processing site contract and capacity attestation
- Restoration test logs with success criteria signed off
- Business impact analysis identifying critical systems
- Backups taken but restore tests never performed end to end
- RTO and RPO targets undefined for tier two systems
- Tabletop exercises lack participation from business owners
- Alternate site capacity not validated against current load
Provide for recovery and reconstitution of system to known state within RTO.
- Control implementation statement for CP-10 citing the system mission and inheritance from common controls
- Backup schedule, retention, and offsite or immutable copy evidence
- Annual tabletop and full failover test reports
- Alternate processing site contract and capacity attestation
- Restoration test logs with success criteria signed off
- Business impact analysis identifying critical systems
- RTO and RPO targets undefined for tier two systems
- Tabletop exercises lack participation from business owners
- Alternate site capacity not validated against current load
- Plan not updated after major architecture changes
System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based
- DB transaction logs
- No transaction replay
Develop contingency plan; review and update annually (FedRAMP); coordinate with related plans.
- Control implementation statement for CP-2 citing the system mission and inheritance from common controls
- Annual tabletop and full failover test reports
- Alternate processing site contract and capacity attestation
- Restoration test logs with success criteria signed off
- Business impact analysis identifying critical systems
- Backups taken but restore tests never performed end to end
- RTO and RPO targets undefined for tier two systems
- Tabletop exercises lack participation from business owners
Coordinate contingency plan with related plans (BCP, DRP, COOP, IRP).
- Coordination matrix
- Siloed plans
Plan for resumption of mission/business functions within FedRAMP-defined time period after contingency plan activation.
- RTO documentation
- RTO undefined
Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions
- BIA criticality map
- No criticality tiers
Provide contingency training to users assigned roles; within FedRAMP timeframe of role assignment and at least annually.
- Control implementation statement for CP-3 citing the system mission and inheritance from common controls
- Alternate processing site contract and capacity attestation
- Restoration test logs with success criteria signed off
- Business impact analysis identifying critical systems
- Contingency plan with recovery time and recovery point objectives
- Backup schedule, retention, and offsite or immutable copy evidence
- RTO and RPO targets undefined for tier two systems
- Tabletop exercises lack participation from business owners
- Alternate site capacity not validated against current load
- Plan not updated after major architecture changes
Test contingency plan at least annually (FedRAMP) using FedRAMP-defined tests; review test results.
- Control implementation statement for CP-4 citing the system mission and inheritance from common controls
- Restoration test logs with success criteria signed off
- Business impact analysis identifying critical systems
- Contingency plan with recovery time and recovery point objectives
- Backup schedule, retention, and offsite or immutable copy evidence
- RTO and RPO targets undefined for tier two systems
- Tabletop exercises lack participation from business owners
- Alternate site capacity not validated against current load
Coordinate contingency plan testing with related plan testing.
- Joint test plan
- Independent testing only
Establish alternate storage site with agreements to permit storage and retrieval of system backup information.
- Control implementation statement for CP-6 citing the system mission and inheritance from common controls
- Contingency plan with recovery time and recovery point objectives
- Backup schedule, retention, and offsite or immutable copy evidence
- Annual tabletop and full failover test reports
- Alternate processing site contract and capacity attestation
- Tabletop exercises lack participation from business owners
- Alternate site capacity not validated against current load
- Plan not updated after major architecture changes
Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats
- Geographic separation evidence
- Same metro zone
Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions
- Accessibility analysis
- No analysis
Establish alternate processing site with agreements for resumption of operations within FedRAMP-defined RTO.
- Control implementation statement for CP-7 citing the system mission and inheritance from common controls
- Backup schedule, retention, and offsite or immutable copy evidence
- Annual tabletop and full failover test reports
- Alternate processing site contract and capacity attestation
- Restoration test logs with success criteria signed off
- Business impact analysis identifying critical systems
- Tabletop exercises lack participation from business owners
- Alternate site capacity not validated against current load
- Plan not updated after major architecture changes
- Backups taken but restore tests never performed end to end
Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats
- Geographic separation
- Same region
Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions
- Accessibility plan
- No plan
Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives)
- SLA priority clause
- No priority clauses
Establish alternate telecommunications services with agreements to permit resumption of system operations.
- Control implementation statement for CP-8 citing the system mission and inheritance from common controls
- Annual tabletop and full failover test reports
- Alternate processing site contract and capacity attestation
- Restoration test logs with success criteria signed off
- Business impact analysis identifying critical systems
- Tabletop exercises lack participation from business owners
- Alternate site capacity not validated against current load
- Plan not updated after major architecture changes
Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and (b) Request Telecommunications Service Priority
- TSP enrollment
- No TSP
Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services
- Diverse routing
- SPOFs unmitigated
Conduct backups of user-level, system-level, and security-related documentation; FedRAMP-defined frequency (daily incremental, weekly full).
- Control implementation statement for CP-9 citing the system mission and inheritance from common controls
- Alternate processing site contract and capacity attestation
- Restoration test logs with success criteria signed off
- Business impact analysis identifying critical systems
- Contingency plan with recovery time and recovery point objectives
- Backup schedule, retention, and offsite or immutable copy evidence
- Alternate site capacity not validated against current load
- Plan not updated after major architecture changes
- Backups taken but restore tests never performed end to end
- RTO and RPO targets undefined for tier two systems
Test backup information annually to verify reliability and integrity.
- Restore test results
- Backups never restored
System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information]
- Backup encryption config
- Unencrypted backups
IA - Identification and Authentication
Develop and review identification and authentication policy at least annually.
- Control implementation statement for IA-1 citing the system mission and inheritance from common controls
- Identity proofing records for high assurance accounts
- Authenticator lifecycle procedure including reset and revocation
- Identification and authentication policy
- MFA enrolment report for all privileged and remote users
- Default vendor credentials remain on appliances and IoT devices
- Password complexity enforced but reuse not blocked across systems
- Federation trust relationships not reviewed when partnerships change
Require re-authentication when FedRAMP-defined circumstances occur (role change, privilege change, time period elapsed).
- Control implementation statement for IA-11 citing the system mission and inheritance from common controls
- Authenticator lifecycle procedure including reset and revocation
- Identification and authentication policy
- MFA enrolment report for all privileged and remote users
- Password policy configuration export from the identity provider
- Service account credential vault inventory and rotation logs
- Password complexity enforced but reuse not blocked across systems
- Federation trust relationships not reviewed when partnerships change
- MFA exceptions granted indefinitely without compensating controls
- Shared accounts authenticate without traceability to individuals
Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a
- Control implementation statement for IA-12 citing the system mission and inheritance from common controls
- Identification and authentication policy
- MFA enrolment report for all privileged and remote users
- Password policy configuration export from the identity provider
- Service account credential vault inventory and rotation logs
- Federation trust relationships not reviewed when partnerships change
- MFA exceptions granted indefinitely without compensating controls
- Shared accounts authenticate without traceability to individuals
Identity Proofing | Identity Evidence. Require evidence of individual identification be presented to the registration authority
- Evidence collection records
- Weak proofing evidence
Identity Proofing | Identity Evidence Validation and Verification. Require that the presented identity evidence be validated and verified through [Assignment: organizational defined methods of validation and verification]
- Validation procedure
- Self-attested only
Identity Proofing | Address Confirmation. Require that a [Selection: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address (physical or digital) of record
- Address confirmation records
- No address confirmation
Uniquely identify and authenticate organizational users and associate identity with processes acting on behalf of users.
- Control implementation statement for IA-2 citing the system mission and inheritance from common controls
- Authenticator lifecycle procedure including reset and revocation
- Identification and authentication policy
- MFA enrolment report for all privileged and remote users
- Password policy configuration export from the identity provider
- Service account credential vault inventory and rotation logs
- Default vendor credentials remain on appliances and IoT devices
- Password complexity enforced but reuse not blocked across systems
- Federation trust relationships not reviewed when partnerships change
- MFA exceptions granted indefinitely without compensating controls
Implement MFA for access to privileged accounts; phishing-resistant per FedRAMP.
- FIDO2/PIV config
- SMS OTP only
Accept and electronically verify Personal Identity Verification credentials.
- PIV reader config
- No PIV support
Implement MFA for non-privileged accounts; phishing-resistant per FedRAMP.
- MFA coverage report
- Exemptions persist
Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources
- Group account handling
- Direct group login
Identification and Authentication (organizational Users) | Access to Accounts , separate Device. Implement multi-factor authentication for [Selection (one or more): local; network; remote] access to [Selection (one or more): privileged accounts; non-privileged accounts] such that:
- Hardware token policy
- Same-device push only
Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.
- Nonce/timestamp auth
- Replayable tokens
Uniquely identify and authenticate devices before establishing connection.
- Control implementation statement for IA-3 citing the system mission and inheritance from common controls
- Identification and authentication policy
- MFA enrolment report for all privileged and remote users
- Password policy configuration export from the identity provider
- Service account credential vault inventory and rotation logs
- Password complexity enforced but reuse not blocked across systems
- Federation trust relationships not reviewed when partnerships change
- MFA exceptions granted indefinitely without compensating controls
Manage identifiers; uniquely identify; prevent reuse for FedRAMP-defined period.
- Control implementation statement for IA-4 citing the system mission and inheritance from common controls
- MFA enrolment report for all privileged and remote users
- Password policy configuration export from the identity provider
- Service account credential vault inventory and rotation logs
- Identity proofing records for high assurance accounts
- Authenticator lifecycle procedure including reset and revocation
- Password complexity enforced but reuse not blocked across systems
- Federation trust relationships not reviewed when partnerships change
- MFA exceptions granted indefinitely without compensating controls
- Shared accounts authenticate without traceability to individuals
Identifier Management | Identify User Status. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status]
- Identifier schema
- No status markers
Manage authenticators; verify identity prior to issuing; establish initial content; protect.
- Control implementation statement for IA-5 citing the system mission and inheritance from common controls
- Password policy configuration export from the identity provider
- Service account credential vault inventory and rotation logs
- Identity proofing records for high assurance accounts
- Authenticator lifecycle procedure including reset and revocation
- Password complexity enforced but reuse not blocked across systems
- Federation trust relationships not reviewed when partnerships change
- MFA exceptions granted indefinitely without compensating controls
Enforce password complexity per NIST SP 800-63B; minimum 12 characters (FedRAMP); compare against breach lists.
- Password policy
- Breach check integration
- No breach checking
Enforce authorized use of public key-based authentication; validate certificates; map identity to account.
- PKI policy
- CRL/OCSP config
- No revocation checking
Protect authenticators commensurate with security category of information they protect.
- Authenticator handling SOP
- Tokens in cleartext
Authenticator Management | No Embedded Unencrypted Static Authenticators. Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage
- Secret scanning results
- Vault adoption
- Hardcoded creds
Obscure authentication feedback during authentication process.
- Control implementation statement for IA-6 citing the system mission and inheritance from common controls
- Service account credential vault inventory and rotation logs
- Identity proofing records for high assurance accounts
- Authenticator lifecycle procedure including reset and revocation
- Identification and authentication policy
- MFA enrolment report for all privileged and remote users
- Federation trust relationships not reviewed when partnerships change
- MFA exceptions granted indefinitely without compensating controls
- Shared accounts authenticate without traceability to individuals
- Default vendor credentials remain on appliances and IoT devices
Implement authentication to cryptographic modules meeting FIPS 140 (FedRAMP requires FIPS-validated).
- Control implementation statement for IA-7 citing the system mission and inheritance from common controls
- Identity proofing records for high assurance accounts
- Authenticator lifecycle procedure including reset and revocation
- Identification and authentication policy
- MFA enrolment report for all privileged and remote users
- Federation trust relationships not reviewed when partnerships change
- MFA exceptions granted indefinitely without compensating controls
- Shared accounts authenticate without traceability to individuals
Uniquely identify and authenticate non-organizational users (e.g., federal customers).
- Control implementation statement for IA-8 citing the system mission and inheritance from common controls
- Authenticator lifecycle procedure including reset and revocation
- Identification and authentication policy
- MFA enrolment report for all privileged and remote users
- Password policy configuration export from the identity provider
- Service account credential vault inventory and rotation logs
- Federation trust relationships not reviewed when partnerships change
- MFA exceptions granted indefinitely without compensating controls
- Shared accounts authenticate without traceability to individuals
- Default vendor credentials remain on appliances and IoT devices
Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies. Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies
- Cross-agency PIV trust
- Internal PIV only
Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators. (a) Accept only external authenticators that are NIST-compliant; and (b) Document and maintain a list of accepted external authenticators
- FICAM-approved IDP list
- Non-FICAM IDP
Identification and Authentication (non-organizational Users) | Use of Defined Profiles. Conform to the following profiles for identity management [Assignment: organization-defined identity management profiles]
- Profile documentation
- No profile mapping
IR - Incident Response
Requires an incident response policy and supporting procedures to be developed, documented, disseminated, reviewed and updated on a defined cycle.
- Control implementation statement for IR-1 citing the system mission and inheritance from common controls
- Incident ticket samples covering detection, containment, and lessons learned
- Forensic toolkit readiness checklist and chain of custody templates
- Regulatory notification procedure with jurisdiction specific timelines
- Incident response plan with severity definitions and escalation paths
- Incident response team roster with on call rotation
- Third party incident responder retainer expired
- Detection coverage gaps allow incidents to be discovered externally
- Severity criteria inconsistent across teams leading to under reporting
- Lessons learned captured but corrective actions not tracked to closure
Requires incident response training for system users consistent with their assigned roles, within a defined period of assuming the role and periodically thereafter.
- Control implementation statement for IR-2 citing the system mission and inheritance from common controls
- Forensic toolkit readiness checklist and chain of custody templates
- Regulatory notification procedure with jurisdiction specific timelines
- Incident response plan with severity definitions and escalation paths
- Incident response team roster with on call rotation
- Third party incident responder retainer expired
- Detection coverage gaps allow incidents to be discovered externally
- Severity criteria inconsistent across teams leading to under reporting
Requires the incident response capability to be tested at a defined frequency using defined tests, to determine its effectiveness, and the results documented.
- Control implementation statement for IR-3 citing the system mission and inheritance from common controls
- Regulatory notification procedure with jurisdiction specific timelines
- Incident response plan with severity definitions and escalation paths
- Incident response team roster with on call rotation
- Tabletop and live exercise after action reports
- Incident ticket samples covering detection, containment, and lessons learned
- Third party incident responder retainer expired
- Detection coverage gaps allow incidents to be discovered externally
- Severity criteria inconsistent across teams leading to under reporting
- Lessons learned captured but corrective actions not tracked to closure
Incident Response Testing | Coordination with Related Plans. Coordinate incident response testing with organizational elements responsible for related plans
- Joint test plan
- Isolated tests
Implement IR capability for preparation, detection/analysis, containment, eradication, recovery.
- Control implementation statement for IR-4 citing the system mission and inheritance from common controls
- Incident response plan with severity definitions and escalation paths
- Incident response team roster with on call rotation
- Tabletop and live exercise after action reports
- Incident ticket samples covering detection, containment, and lessons learned
- Detection coverage gaps allow incidents to be discovered externally
- Severity criteria inconsistent across teams leading to under reporting
- Lessons learned captured but corrective actions not tracked to closure
Support incident handling via automated mechanisms.
- SOAR playbooks
- Manual-only handling
Track and document incidents.
- Control implementation statement for IR-5 citing the system mission and inheritance from common controls
- Incident response team roster with on call rotation
- Tabletop and live exercise after action reports
- Incident ticket samples covering detection, containment, and lessons learned
- Forensic toolkit readiness checklist and chain of custody templates
- Regulatory notification procedure with jurisdiction specific timelines
- Detection coverage gaps allow incidents to be discovered externally
- Severity criteria inconsistent across teams leading to under reporting
- Lessons learned captured but corrective actions not tracked to closure
- Notification timelines miss jurisdictional regulatory deadlines
Require personnel to report incidents to organizational authorities within FedRAMP timeframe; report to FedRAMP PMO and US-CERT.
- Control implementation statement for IR-6 citing the system mission and inheritance from common controls
- Tabletop and live exercise after action reports
- Incident ticket samples covering detection, containment, and lessons learned
- Forensic toolkit readiness checklist and chain of custody templates
- Regulatory notification procedure with jurisdiction specific timelines
- Detection coverage gaps allow incidents to be discovered externally
- Severity criteria inconsistent across teams leading to under reporting
- Lessons learned captured but corrective actions not tracked to closure
Report incidents via automated mechanisms.
- Automated reporting workflow
- Manual email reports
Incident Reporting | Supply Chain Coordination. Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components
- Supplier notification log
- No supplier coordination
Provide IR support resource (help desk, support group) for incident handling assistance.
- Control implementation statement for IR-7 citing the system mission and inheritance from common controls
- Incident ticket samples covering detection, containment, and lessons learned
- Forensic toolkit readiness checklist and chain of custody templates
- Regulatory notification procedure with jurisdiction specific timelines
- Incident response plan with severity definitions and escalation paths
- Incident response team roster with on call rotation
- Severity criteria inconsistent across teams leading to under reporting
- Lessons learned captured but corrective actions not tracked to closure
- Notification timelines miss jurisdictional regulatory deadlines
- Third party incident responder retainer expired
Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms]
- Knowledge base
- No automated KB
Develop and implement IRP; review and update annually; distribute.
- Control implementation statement for IR-8 citing the system mission and inheritance from common controls
- Forensic toolkit readiness checklist and chain of custody templates
- Regulatory notification procedure with jurisdiction specific timelines
- Incident response plan with severity definitions and escalation paths
- Incident response team roster with on call rotation
- Severity criteria inconsistent across teams leading to under reporting
- Lessons learned captured but corrective actions not tracked to closure
- Notification timelines miss jurisdictional regulatory deadlines
Information Spillage Response. Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to information spills; b. Identifying the specific information involved in the system contamination; c. Alerting
- Spill response procedure
- No spill procedure
Information Spillage Response | Training. Provide information spillage response training [Assignment: organization-defined frequency]
- Spill training records
- No spill training
Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks while contaminated systems are undergoing corrective actions: [Assignment:
- Post-spill procedure
- Personnel locked out
Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls]
- Exposure handling SOP
- No safeguards
MA - Maintenance
Develop and review maintenance policy at least annually.
- Control implementation statement for MA-1 citing the system mission and inheritance from common controls
- Maintenance personnel access list with background check status
- Remote maintenance session logs with MFA and supervision evidence
- Tool sanitisation records for media leaving the facility
- Vendor maintenance agreements with security clauses
- Emergency maintenance performed without retrospective documentation
- Maintenance vendors lack signed confidentiality and security clauses
- Vendor engineers granted standing access rather than session based access
Schedule, document, review records of maintenance, repair, replacement of components.
- Control implementation statement for MA-2 citing the system mission and inheritance from common controls
- Remote maintenance session logs with MFA and supervision evidence
- Tool sanitisation records for media leaving the facility
- Vendor maintenance agreements with security clauses
- System maintenance policy and approved maintenance windows
- Maintenance ticket records with approvals and post change verification
- Maintenance vendors lack signed confidentiality and security clauses
- Vendor engineers granted standing access rather than session based access
- Remote maintenance sessions unmonitored after initial authentication
- Maintenance tools not sanitised before removal from secure areas
Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]
- Control implementation statement for MA-3 citing the system mission and inheritance from common controls
- Tool sanitisation records for media leaving the facility
- Vendor maintenance agreements with security clauses
- System maintenance policy and approved maintenance windows
- Maintenance ticket records with approvals and post change verification
- Maintenance vendors lack signed confidentiality and security clauses
- Vendor engineers granted standing access rather than session based access
- Remote maintenance sessions unmonitored after initial authentication
Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications
- Tool inspection records
- No inspections
Maintenance Tools | Inspect Media. Check media containing diagnostic and test programs for malicious code before the media are used in the system
- Media scan logs
- No media scanning
Maintenance Tools | Prevent Unauthorized Removal. Prevent the removal of maintenance equipment containing organizational information by: (a) Verifying that there is no organizational information contained on the equipment; (b) Sanitizing or destroying the equipment;
- Removal procedure
- No removal control
Approve and monitor nonlocal maintenance activities; use strong authentication.
- Control implementation statement for MA-4 citing the system mission and inheritance from common controls
- Vendor maintenance agreements with security clauses
- System maintenance policy and approved maintenance windows
- Maintenance ticket records with approvals and post change verification
- Maintenance personnel access list with background check status
- Remote maintenance session logs with MFA and supervision evidence
- Maintenance vendors lack signed confidentiality and security clauses
- Vendor engineers granted standing access rather than session based access
- Remote maintenance sessions unmonitored after initial authentication
- Maintenance tools not sanitised before removal from secure areas
Establish process for authorizing maintenance personnel; maintain list of authorized personnel; supervise unauthorized.
- Control implementation statement for MA-5 citing the system mission and inheritance from common controls
- System maintenance policy and approved maintenance windows
- Maintenance ticket records with approvals and post change verification
- Maintenance personnel access list with background check status
- Remote maintenance session logs with MFA and supervision evidence
- Vendor engineers granted standing access rather than session based access
- Remote maintenance sessions unmonitored after initial authentication
- Maintenance tools not sanitised before removal from secure areas
Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clearances or are not U.S. citizens, that include the following requirements: (1)
- Escort procedure
- Unescorted vendors
Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure
- Support contracts
- No SLA
MP - Media Protection
Develop and review media protection policy at least annually.
- Control implementation statement for MP-1 citing the system mission and inheritance from common controls
- Encryption configuration for portable storage devices
- Media protection policy covering electronic and physical media
- Media inventory and labelling scheme by data classification
- Sanitisation and destruction certificates from approved disposal vendor
- Removable media usage policy and DLP enforcement evidence
- Backup tapes shipped without tamper evident packaging
- Media classification labels missing on physical assets
- Decommissioned drives stored unencrypted while awaiting destruction
- USB usage permitted without DLP inspection or encryption
Restrict access to FedRAMP-defined types of digital and non-digital media to authorized personnel.
- Control implementation statement for MP-2 citing the system mission and inheritance from common controls
- Media protection policy covering electronic and physical media
- Media inventory and labelling scheme by data classification
- Sanitisation and destruction certificates from approved disposal vendor
- Removable media usage policy and DLP enforcement evidence
- Media classification labels missing on physical assets
- Decommissioned drives stored unencrypted while awaiting destruction
- USB usage permitted without DLP inspection or encryption
Mark system media indicating distribution limitations, handling caveats, security markings.
- Control implementation statement for MP-3 citing the system mission and inheritance from common controls
- Media inventory and labelling scheme by data classification
- Sanitisation and destruction certificates from approved disposal vendor
- Removable media usage policy and DLP enforcement evidence
- Media transport chain of custody logs
- Encryption configuration for portable storage devices
- Media classification labels missing on physical assets
- Decommissioned drives stored unencrypted while awaiting destruction
- USB usage permitted without DLP inspection or encryption
- Destruction certificates lack serial numbers tying back to inventory
Physically control and securely store FedRAMP-defined types of media within FedRAMP-defined controlled areas.
- Control implementation statement for MP-4 citing the system mission and inheritance from common controls
- Sanitisation and destruction certificates from approved disposal vendor
- Removable media usage policy and DLP enforcement evidence
- Media transport chain of custody logs
- Encryption configuration for portable storage devices
- Media classification labels missing on physical assets
- Decommissioned drives stored unencrypted while awaiting destruction
- USB usage permitted without DLP inspection or encryption
Protect and control media during transport outside controlled areas; maintain accountability; document activities; restrict transport to authorized personnel.
- Control implementation statement for MP-5 citing the system mission and inheritance from common controls
- Removable media usage policy and DLP enforcement evidence
- Media transport chain of custody logs
- Encryption configuration for portable storage devices
- Media protection policy covering electronic and physical media
- Media inventory and labelling scheme by data classification
- Decommissioned drives stored unencrypted while awaiting destruction
- USB usage permitted without DLP inspection or encryption
- Destruction certificates lack serial numbers tying back to inventory
- Backup tapes shipped without tamper evident packaging
Sanitize media prior to disposal, release, or reuse using FedRAMP-defined methods (NIST SP 800-88).
- Control implementation statement for MP-6 citing the system mission and inheritance from common controls
- Media transport chain of custody logs
- Encryption configuration for portable storage devices
- Media protection policy covering electronic and physical media
- Media inventory and labelling scheme by data classification
- Decommissioned drives stored unencrypted while awaiting destruction
- USB usage permitted without DLP inspection or encryption
- Destruction certificates lack serial numbers tying back to inventory
Restrict or prohibit use of FedRAMP-defined types of media on FedRAMP-defined systems using safeguards.
- Control implementation statement for MP-7 citing the system mission and inheritance from common controls
- Encryption configuration for portable storage devices
- Media protection policy covering electronic and physical media
- Media inventory and labelling scheme by data classification
- Sanitisation and destruction certificates from approved disposal vendor
- Removable media usage policy and DLP enforcement evidence
- Decommissioned drives stored unencrypted while awaiting destruction
- USB usage permitted without DLP inspection or encryption
- Destruction certificates lack serial numbers tying back to inventory
- Backup tapes shipped without tamper evident packaging
PE - Physical and Environmental Protection
Develop and review physical/environmental policy at least annually.
- Control implementation statement for PE-1 citing the system mission and inheritance from common controls
- CCTV retention configuration and footage spot check evidence
- Environmental monitoring readings for temperature, humidity, and water leak sensors
- Fire suppression and UPS maintenance records
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- Visitor logs incomplete or escort sign offs missing
- Environmental sensor alerts route to unmonitored mailboxes
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system
- Control implementation statement for PE-10 citing the system mission and inheritance from common controls
- CCTV retention configuration and footage spot check evidence
- Environmental monitoring readings for temperature, humidity, and water leak sensors
- Fire suppression and UPS maintenance records
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- Environmental sensor alerts route to unmonitored mailboxes
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
- Tailgating observed without challenge during walkthroughs
Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power
- Control implementation statement for PE-11 citing the system mission and inheritance from common controls
- Environmental monitoring readings for temperature, humidity, and water leak sensors
- Fire suppression and UPS maintenance records
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- Environmental sensor alerts route to unmonitored mailboxes
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
Employ and maintain automatic emergency lighting activating on power outage covering emergency exits.
- Control implementation statement for PE-12 citing the system mission and inheritance from common controls
- Fire suppression and UPS maintenance records
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- Visitor sign in records with escort assignment
- CCTV retention configuration and footage spot check evidence
- Environmental sensor alerts route to unmonitored mailboxes
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
- Tailgating observed without challenge during walkthroughs
Employ and maintain fire suppression and detection devices independent of energy source.
- Control implementation statement for PE-13 citing the system mission and inheritance from common controls
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- Visitor sign in records with escort assignment
- CCTV retention configuration and footage spot check evidence
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
- Tailgating observed without challenge during walkthroughs
Fire Protection | Detection Systems. Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a
- Alarm escalation
- No escalation list
Fire Protection | Suppression Systems. Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an
- Automatic suppression
- Manual only
Maintain temperature and humidity within FedRAMP-defined acceptable levels; monitor at FedRAMP frequency.
- Control implementation statement for PE-14 citing the system mission and inheritance from common controls
- Badge access system audit log and door alarm reports
- Visitor sign in records with escort assignment
- CCTV retention configuration and footage spot check evidence
- Environmental monitoring readings for temperature, humidity, and water leak sensors
- Fire suppression and UPS maintenance records
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
- Tailgating observed without challenge during walkthroughs
- Visitor logs incomplete or escort sign offs missing
Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel
- Control implementation statement for PE-15 citing the system mission and inheritance from common controls
- Visitor sign in records with escort assignment
- CCTV retention configuration and footage spot check evidence
- Environmental monitoring readings for temperature, humidity, and water leak sensors
- Fire suppression and UPS maintenance records
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
- Tailgating observed without challenge during walkthroughs
Authorize and control system components entering/exiting facility; maintain records.
- Inventory in/out logs
- No records
Determine alternate work sites; employ FedRAMP-defined controls at alternate sites; assess effectiveness.
- Control implementation statement for PE-17 citing the system mission and inheritance from common controls
- Environmental monitoring readings for temperature, humidity, and water leak sensors
- Fire suppression and UPS maintenance records
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- CCTV coverage gaps at loading docks and equipment delivery areas
- Tailgating observed without challenge during walkthroughs
- Visitor logs incomplete or escort sign offs missing
Develop, approve, maintain list of individuals with authorized facility access; review at least quarterly (FedRAMP).
- Control implementation statement for PE-2 citing the system mission and inheritance from common controls
- Environmental monitoring readings for temperature, humidity, and water leak sensors
- Fire suppression and UPS maintenance records
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- Visitor logs incomplete or escort sign offs missing
- Environmental sensor alerts route to unmonitored mailboxes
- Server room doors propped open during cooling failures
Enforce physical access at entry/exit points; verify authorizations; control ingress/egress; maintain audit logs.
- Control implementation statement for PE-3 citing the system mission and inheritance from common controls
- Fire suppression and UPS maintenance records
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- Visitor sign in records with escort assignment
- CCTV retention configuration and footage spot check evidence
- Visitor logs incomplete or escort sign offs missing
- Environmental sensor alerts route to unmonitored mailboxes
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls]
- Control implementation statement for PE-4 citing the system mission and inheritance from common controls
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- Visitor sign in records with escort assignment
- CCTV retention configuration and footage spot check evidence
- Environmental sensor alerts route to unmonitored mailboxes
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output
- Control implementation statement for PE-5 citing the system mission and inheritance from common controls
- Badge access system audit log and door alarm reports
- Visitor sign in records with escort assignment
- CCTV retention configuration and footage spot check evidence
- Environmental monitoring readings for temperature, humidity, and water leak sensors
- Fire suppression and UPS maintenance records
- Environmental sensor alerts route to unmonitored mailboxes
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
- Tailgating observed without challenge during walkthroughs
Monitor physical access to facility; review access logs at least weekly (FedRAMP); coordinate review with IR.
- Control implementation statement for PE-6 citing the system mission and inheritance from common controls
- Visitor sign in records with escort assignment
- CCTV retention configuration and footage spot check evidence
- Environmental monitoring readings for temperature, humidity, and water leak sensors
- Fire suppression and UPS maintenance records
- Environmental sensor alerts route to unmonitored mailboxes
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment. Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment
- CCTV deployment
- No surveillance
Maintain visitor access records for FedRAMP-defined period (1 year); review records monthly (FedRAMP).
- Control implementation statement for PE-8 citing the system mission and inheritance from common controls
- Environmental monitoring readings for temperature, humidity, and water leak sensors
- Fire suppression and UPS maintenance records
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
- Tailgating observed without challenge during walkthroughs
Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction
- Control implementation statement for PE-9 citing the system mission and inheritance from common controls
- Fire suppression and UPS maintenance records
- Physical security policy and facility risk assessment
- Badge access system audit log and door alarm reports
- Visitor sign in records with escort assignment
- CCTV retention configuration and footage spot check evidence
- Server room doors propped open during cooling failures
- CCTV coverage gaps at loading docks and equipment delivery areas
- Tailgating observed without challenge during walkthroughs
- Visitor logs incomplete or escort sign offs missing
PL - Planning
Develop and review planning policy at least annually.
- Control implementation statement for PL-1 citing the system mission and inheritance from common controls
- Concept of operations describing system mission and data flows
- Privacy and security integration documentation
- System security plan with control allocation matrix
- Rules of behaviour signed by users including privileged personnel
- Planning artefacts lack version history and approval signatures
- Privacy considerations addressed separately from security planning
- System security plan not refreshed after material system changes
Baseline Selection. Select a control baseline for the system
- Control implementation statement for PL-10 citing the system mission and inheritance from common controls
- Concept of operations describing system mission and data flows
- Privacy and security integration documentation
- System security plan with control allocation matrix
- Rules of behaviour signed by users including privileged personnel
- Privacy considerations addressed separately from security planning
- System security plan not refreshed after material system changes
- Rules of behaviour acknowledged once but not refreshed annually
Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions
- Control implementation statement for PL-11 citing the system mission and inheritance from common controls
- Privacy and security integration documentation
- System security plan with control allocation matrix
- Rules of behaviour signed by users including privileged personnel
- Information security architecture diagrams current within twelve months
- Security planning meeting minutes with stakeholder attendance
- Privacy considerations addressed separately from security planning
- System security plan not refreshed after material system changes
- Rules of behaviour acknowledged once but not refreshed annually
- Architecture diagrams missing third party and SaaS dependencies
Develop SSP that aligns with FedRAMP template; review and update annually.
- Control implementation statement for PL-2 citing the system mission and inheritance from common controls
- Privacy and security integration documentation
- System security plan with control allocation matrix
- Rules of behaviour signed by users including privileged personnel
- Information security architecture diagrams current within twelve months
- Security planning meeting minutes with stakeholder attendance
- Planning artefacts lack version history and approval signatures
- Privacy considerations addressed separately from security planning
- System security plan not refreshed after material system changes
- Rules of behaviour acknowledged once but not refreshed annually
Establish and provide rules describing user responsibilities; receive signed acknowledgement.
- Control implementation statement for PL-4 citing the system mission and inheritance from common controls
- Rules of behaviour signed by users including privileged personnel
- Information security architecture diagrams current within twelve months
- Security planning meeting minutes with stakeholder attendance
- Concept of operations describing system mission and data flows
- Privacy and security integration documentation
- Privacy considerations addressed separately from security planning
- System security plan not refreshed after material system changes
- Rules of behaviour acknowledged once but not refreshed annually
- Architecture diagrams missing third party and SaaS dependencies
Rules of Behavior | Social Media and External Site/application Usage Restrictions. Include in the rules of behavior, restrictions on: (a) Use of social media, social networking sites, and external sites/applications; (b) Posting organizational information
- Social media clause
- Generic RoB
Develop, document, maintain security/privacy architectures; review annually.
- Control implementation statement for PL-8 citing the system mission and inheritance from common controls
- Privacy and security integration documentation
- System security plan with control allocation matrix
- Rules of behaviour signed by users including privileged personnel
- Information security architecture diagrams current within twelve months
- Security planning meeting minutes with stakeholder attendance
- System security plan not refreshed after material system changes
- Rules of behaviour acknowledged once but not refreshed annually
- Architecture diagrams missing third party and SaaS dependencies
- Planning artefacts lack version history and approval signatures
PS - Personnel Security
Develop and review personnel security policy at least annually.
- Control implementation statement for PS-1 citing the system mission and inheritance from common controls
- Acknowledgement of access agreements signed at hire
- Personnel security policy and position risk designation matrix
- Background screening completion records by role tier
- Termination and transfer access removal evidence within SLA
- Sanctions policy with documented application history
- Background checks not re run when employees move to higher risk roles
- Termination access removal exceeds documented SLA
- Sanctions applied informally without HR documentation
- Contractor screening relies on vendor attestation without sampling
Assign risk designation to positions; review and update at least every three years.
- Control implementation statement for PS-2 citing the system mission and inheritance from common controls
- Personnel security policy and position risk designation matrix
- Background screening completion records by role tier
- Termination and transfer access removal evidence within SLA
- Sanctions policy with documented application history
- Termination access removal exceeds documented SLA
- Sanctions applied informally without HR documentation
- Contractor screening relies on vendor attestation without sampling
Screen individuals prior to authorizing access; rescreen at FedRAMP frequency per position risk; US citizenship may apply.
- Control implementation statement for PS-3 citing the system mission and inheritance from common controls
- Background screening completion records by role tier
- Termination and transfer access removal evidence within SLA
- Sanctions policy with documented application history
- Third party personnel screening attestations
- Acknowledgement of access agreements signed at hire
- Termination access removal exceeds documented SLA
- Sanctions applied informally without HR documentation
- Contractor screening relies on vendor attestation without sampling
- Position risk designations not reviewed when responsibilities change
Personnel Screening | Information Requiring Special Protective Measures. Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection: (a) Have valid access authorizations that are demonstrated by assigned official government
- Special access agreements
- No special handling
Disable access and revoke authenticators within FedRAMP-defined time (same day); conduct exit interview; retrieve property.
- Control implementation statement for PS-4 citing the system mission and inheritance from common controls
- Termination and transfer access removal evidence within SLA
- Sanctions policy with documented application history
- Third party personnel screening attestations
- Acknowledgement of access agreements signed at hire
- Termination access removal exceeds documented SLA
- Sanctions applied informally without HR documentation
- Contractor screening relies on vendor attestation without sampling
Review/confirm ongoing operational need for access when personnel transfer; modify access; notify within FedRAMP timeframe.
- Control implementation statement for PS-5 citing the system mission and inheritance from common controls
- Sanctions policy with documented application history
- Third party personnel screening attestations
- Acknowledgement of access agreements signed at hire
- Personnel security policy and position risk designation matrix
- Background screening completion records by role tier
- Sanctions applied informally without HR documentation
- Contractor screening relies on vendor attestation without sampling
- Position risk designations not reviewed when responsibilities change
- Background checks not re run when employees move to higher risk roles
Develop access agreements; review and update annually; require signature before access.
- Control implementation statement for PS-6 citing the system mission and inheritance from common controls
- Third party personnel screening attestations
- Acknowledgement of access agreements signed at hire
- Personnel security policy and position risk designation matrix
- Background screening completion records by role tier
- Sanctions applied informally without HR documentation
- Contractor screening relies on vendor attestation without sampling
- Position risk designations not reviewed when responsibilities change
Establish personnel security requirements for external providers; require providers to notify within FedRAMP timeframe of personnel changes.
- Control implementation statement for PS-7 citing the system mission and inheritance from common controls
- Acknowledgement of access agreements signed at hire
- Personnel security policy and position risk designation matrix
- Background screening completion records by role tier
- Termination and transfer access removal evidence within SLA
- Sanctions policy with documented application history
- Sanctions applied informally without HR documentation
- Contractor screening relies on vendor attestation without sampling
- Position risk designations not reviewed when responsibilities change
- Background checks not re run when employees move to higher risk roles
Employ formal sanctions for personnel failing to comply with security/privacy policies; notify defined personnel within FedRAMP timeframe.
- Control implementation statement for PS-8 citing the system mission and inheritance from common controls
- Personnel security policy and position risk designation matrix
- Background screening completion records by role tier
- Termination and transfer access removal evidence within SLA
- Sanctions policy with documented application history
- Contractor screening relies on vendor attestation without sampling
- Position risk designations not reviewed when responsibilities change
- Background checks not re run when employees move to higher risk roles
Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions
- Control implementation statement for PS-9 citing the system mission and inheritance from common controls
- Background screening completion records by role tier
- Termination and transfer access removal evidence within SLA
- Sanctions policy with documented application history
- Third party personnel screening attestations
- Acknowledgement of access agreements signed at hire
- Contractor screening relies on vendor attestation without sampling
- Position risk designations not reviewed when responsibilities change
- Background checks not re run when employees move to higher risk roles
- Termination access removal exceeds documented SLA
RA - Risk Assessment
Develop and review risk assessment policy at least annually.
- Control implementation statement for RA-1 citing the system mission and inheritance from common controls
- Risk register with likelihood, impact, and treatment owners
- Vulnerability scan reports for internal, external, and authenticated scopes
- Penetration test report with retest evidence
- Threat intelligence feed subscriptions and triage workflow
- Risk acceptance memos signed by accountable executives
- High severity vulnerabilities exceed remediation SLA without risk acceptance
- Risk register entries lack named owner or due date
- Penetration tests scope narrow and exclude key applications
- Scan coverage gaps for containerised and ephemeral workloads
Categorize system per FIPS 199; document; review and update annually.
- Control implementation statement for RA-2 citing the system mission and inheritance from common controls
- Vulnerability scan reports for internal, external, and authenticated scopes
- Penetration test report with retest evidence
- Threat intelligence feed subscriptions and triage workflow
- Risk acceptance memos signed by accountable executives
- High severity vulnerabilities exceed remediation SLA without risk acceptance
- Risk register entries lack named owner or due date
- Penetration tests scope narrow and exclude key applications
Conduct risk assessment annually (FedRAMP); document; review and update.
- Control implementation statement for RA-3 citing the system mission and inheritance from common controls
- Penetration test report with retest evidence
- Threat intelligence feed subscriptions and triage workflow
- Risk acceptance memos signed by accountable executives
- Risk assessment methodology approved by leadership
- Risk register with likelihood, impact, and treatment owners
- Risk register entries lack named owner or due date
- Penetration tests scope narrow and exclude key applications
- Scan coverage gaps for containerised and ephemeral workloads
- Threat intelligence consumed but not operationalised into detections
Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; and (b) Update the supply chain risk assessment [Assignment: organization-defined frequency], when
- SCRM assessment
- No SCRM
Scan for vulnerabilities monthly (FedRAMP); OS/network weekly, web app monthly, database monthly; remediate within FedRAMP timeframes (HIGH critical 15d, high 30d).
- Control implementation statement for RA-5 citing the system mission and inheritance from common controls
- Risk acceptance memos signed by accountable executives
- Risk assessment methodology approved by leadership
- Risk register with likelihood, impact, and treatment owners
- Vulnerability scan reports for internal, external, and authenticated scopes
- Penetration test report with retest evidence
- Risk register entries lack named owner or due date
- Penetration tests scope narrow and exclude key applications
- Scan coverage gaps for containerised and ephemeral workloads
- Threat intelligence consumed but not operationalised into detections
Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components
- VDP page
- Triage SOP
- No VDP
Update vulnerability list prior to scan, when new vulnerabilities identified, or at FedRAMP frequency.
- Scanner update schedule
- Stale signatures
Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage
- The documented definition of breadth and depth of vulnerability scanning coverage, stating which components and which vulnerability classes are in scope
- Scanner configuration showing the target scope and the checks enabled, matched against that definition
- Scan results demonstrating the defined breadth was actually reached, with an accounted list of assets not scanned
- Reconciliation of scan targets against the system component inventory
- Evidence of authenticated scanning where depth requires it, and the credentials scope used
- Breadth and depth asserted from the tool default rather than defined by the organisation, which is exactly what this enhancement requires
- Scan coverage never reconciled against the asset inventory, so unscanned hosts are invisible
- Unauthenticated scanning presented as satisfying depth, missing configuration and patch level findings
Implement privileged access authorization to FedRAMP-defined components for vulnerability scanning.
- Authenticated scan config
- Unauthenticated scans only
Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or system services] at [Assignment: organization-defined decision points in the system development life cycle]
- Control implementation statement for RA-9 citing the system mission and inheritance from common controls
- Penetration test report with retest evidence
- Threat intelligence feed subscriptions and triage workflow
- Risk acceptance memos signed by accountable executives
- Risk assessment methodology approved by leadership
- Risk register with likelihood, impact, and treatment owners
- Scan coverage gaps for containerised and ephemeral workloads
- Threat intelligence consumed but not operationalised into detections
- High severity vulnerabilities exceed remediation SLA without risk acceptance
- Risk register entries lack named owner or due date
Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so that identified risk is treated rather than only recorded.
- risk response plan or POA&M showing decisions per finding
- evidence findings from assessments and continuous monitoring feed the response process
- records showing accepted risks are approved at the right level
- findings logged but never dispositioned
- risk acceptance without documented authority
- no link between monitoring output and response decisions
SA - System and Services Acquisition
Requires a system and services acquisition policy and supporting procedures to be developed, documented, disseminated, reviewed and updated on a defined cycle.
- Control implementation statement for SA-1 citing the system mission and inheritance from common controls
- Threat modelling and design review evidence for major releases
- Static and dynamic code analysis reports with finding remediation
- Vendor security questionnaires and SOC reports retained
- Software bill of materials for in scope products
- Security requirements absent from procurement templates for low value buys
- Threat modelling performed inconsistently across product teams
- Open source components used without SBOM or licence review
Require developer to perform CM during development, implementation, operation; document/track changes; implement only approved changes.
- Control implementation statement for SA-10 citing the system mission and inheritance from common controls
- Threat modelling and design review evidence for major releases
- Static and dynamic code analysis reports with finding remediation
- Vendor security questionnaires and SOC reports retained
- Software bill of materials for in scope products
- Threat modelling performed inconsistently across product teams
- Open source components used without SBOM or licence review
- Vendor SOC reports collected but exceptions not analysed
Require developer to test at FedRAMP-defined depth and coverage; document; correct flaws.
- Control implementation statement for SA-11 citing the system mission and inheritance from common controls
- Static and dynamic code analysis reports with finding remediation
- Vendor security questionnaires and SOC reports retained
- Software bill of materials for in scope products
- Acquisition policy with security clauses for contracts
- Secure software development lifecycle procedures
- Open source components used without SBOM or licence review
- Vendor SOC reports collected but exceptions not analysed
- Code scan findings closed without verification of fix
- Security requirements absent from procurement templates for low value buys
Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of
- SAST results
- No SAST
Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing
- Threat models
- No threat modeling
Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the
- Control implementation statement for SA-15 citing the system mission and inheritance from common controls
- Secure software development lifecycle procedures
- Threat modelling and design review evidence for major releases
- Static and dynamic code analysis reports with finding remediation
- Vendor security questionnaires and SOC reports retained
- Software bill of materials for in scope products
- Vendor SOC reports collected but exceptions not analysed
- Code scan findings closed without verification of fix
- Security requirements absent from procurement templates for low value buys
- Threat modelling performed inconsistently across product teams
Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At the following decision points in the system development
- Contract or solicitation clause requiring the developer to perform criticality analysis
- The developer's criticality analysis output identifying critical components and functions
- Evidence the analysis was performed at the defined decision points in the development life cycle
- Evidence the analysis was performed at the defined level of detail or decomposition
- Organisational review of the developer's analysis and the actions taken on its findings
- Analysis delivered once at design with no repeat at the later decision points the requirement names
- Decomposition stopped at the subsystem level, so the critical component inside it is never identified
- Developer output accepted with no organisational review, so criticality findings drive no acquisition decision
Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning; determine, document and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process; and establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.
- Mission and business process planning documentation recording the high-level information security and privacy requirements determined for the system or system service
- Capital planning and investment control submission or business case showing the resources determined, documented and allocated to protect the system or system service
- Programming and budgeting documentation showing a discrete line item for information security and privacy
- Approved budget or spend plan carrying that line item, with its approval record
- System security and privacy plan section recording the allocated resources and the basis for the amount
- Records of review of the allocation when requirements or the system change across the system development life cycle
- Security and privacy requirements determined after the acquisition decision rather than during mission and business process planning
- Security funding absorbed into a general IT or infrastructure line, so no discrete information security and privacy item exists to evidence
- Resources named in a plan but never traced through to an approved budget or capital planning submission
- Privacy resourcing omitted while security resourcing is documented, although the control covers both
- Line item established once at authorization and not maintained through sustainment and supply chain activity
Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support
- Control implementation statement for SA-22 citing the system mission and inheritance from common controls
- Software bill of materials for in scope products
- Acquisition policy with security clauses for contracts
- Secure software development lifecycle procedures
- Threat modelling and design review evidence for major releases
- Static and dynamic code analysis reports with finding remediation
- Open source components used without SBOM or licence review
- Vendor SOC reports collected but exceptions not analysed
- Code scan findings closed without verification of fix
- Security requirements absent from procurement templates for low value buys
Manage system using SDLC incorporating security/privacy considerations.
- Control implementation statement for SA-3 citing the system mission and inheritance from common controls
- Vendor security questionnaires and SOC reports retained
- Software bill of materials for in scope products
- Acquisition policy with security clauses for contracts
- Secure software development lifecycle procedures
- Threat modelling performed inconsistently across product teams
- Open source components used without SBOM or licence review
- Vendor SOC reports collected but exceptions not analysed
Include security/privacy requirements in contracts; FedRAMP-defined assurance requirements.
- Control implementation statement for SA-4 citing the system mission and inheritance from common controls
- Software bill of materials for in scope products
- Acquisition policy with security clauses for contracts
- Secure software development lifecycle procedures
- Threat modelling and design review evidence for major releases
- Static and dynamic code analysis reports with finding remediation
- Threat modelling performed inconsistently across product teams
- Open source components used without SBOM or licence review
- Vendor SOC reports collected but exceptions not analysed
- Code scan findings closed without verification of fix
Acquisition Process | Functional Properties of Controls. Require the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be implemented
- Control descriptions
- Generic vendor docs
Employ only information technology products on FIPS 201-approved products list for PIV capability.
- APL evidence
- Non-APL products
Acquisition Process | Design and Implementation Information for Controls. Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: [Selection (one or
- Design docs
- No design info
Acquisition Process | Functions, Ports, Protocols, and Services in Use. Require the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organizational use
- PPS list
- Undocumented PPS
Obtain administrator and user documentation; protect; distribute to FedRAMP-defined personnel.
- Control implementation statement for SA-5 citing the system mission and inheritance from common controls
- Acquisition policy with security clauses for contracts
- Secure software development lifecycle procedures
- Threat modelling and design review evidence for major releases
- Static and dynamic code analysis reports with finding remediation
- Open source components used without SBOM or licence review
- Vendor SOC reports collected but exceptions not analysed
- Code scan findings closed without verification of fix
Apply FedRAMP-defined systems security and privacy engineering principles in development.
- Control implementation statement for SA-8 citing the system mission and inheritance from common controls
- Static and dynamic code analysis reports with finding remediation
- Vendor security questionnaires and SOC reports retained
- Software bill of materials for in scope products
- Acquisition policy with security clauses for contracts
- Secure software development lifecycle procedures
- Vendor SOC reports collected but exceptions not analysed
- Code scan findings closed without verification of fix
- Security requirements absent from procurement templates for low value buys
- Threat modelling performed inconsistently across product teams
Require providers of external system services to comply with security/privacy requirements; document oversight roles.
- Control implementation statement for SA-9 citing the system mission and inheritance from common controls
- Vendor security questionnaires and SOC reports retained
- Software bill of materials for in scope products
- Acquisition policy with security clauses for contracts
- Secure software development lifecycle procedures
- Vendor SOC reports collected but exceptions not analysed
- Code scan findings closed without verification of fix
- Security requirements absent from procurement templates for low value buys
External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and (b) Verify that the acquisition or outsourcing
- Pre-acquisition RA
- No pre-procurement RA
Require providers to identify functions, ports, protocols, services required for external services.
- PPS documentation
- Undocumented
External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or
- US-only attestation
- Foreign data residency
SC - System and Communications Protection
Develop and review system/comms protection policy at least annually.
- Control implementation statement for SC-1 citing the system mission and inheritance from common controls
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Flat networks expose sensitive workloads without segmentation
- Cryptographic keys stored alongside the data they protect
- Firewall rule base contains stale allow any entries
Terminate network connection at end of session or after FedRAMP-defined inactivity period (no longer than 30 minutes).
- Control implementation statement for SC-10 citing the system mission and inheritance from common controls
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Cryptographic keys stored alongside the data they protect
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
Establish and manage cryptographic keys per FedRAMP requirements (FIPS-validated, key escrow/recovery as appropriate).
- Control implementation statement for SC-12 citing the system mission and inheritance from common controls
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
Implement FedRAMP-defined cryptographic uses and approved cryptography (FIPS 140 validated).
- Control implementation statement for SC-13 citing the system mission and inheritance from common controls
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
- Flat networks expose sensitive workloads without segmentation
Prohibit remote activation of collaborative computing devices (cameras, mics) without explicit user indication; provide explicit notification.
- Control implementation statement for SC-15 citing the system mission and inheritance from common controls
- TLS configuration scan results across in scope endpoints
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
- Flat networks expose sensitive workloads without segmentation
- Cryptographic keys stored alongside the data they protect
Issue public key certificates under FedRAMP-defined policy or obtain from approved service providers.
- Control implementation statement for SC-17 citing the system mission and inheritance from common controls
- Denial of service protection configuration and capacity test results
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
- Flat networks expose sensitive workloads without segmentation
- Cryptographic keys stored alongside the data they protect
Define acceptable and unacceptable mobile code; authorize use; monitor.
- Mobile code policy
- No policy
Separate user functionality from system management functionality.
- Control implementation statement for SC-2 citing the system mission and inheritance from common controls
- Denial of service protection configuration and capacity test results
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Flat networks expose sensitive workloads without segmentation
- Cryptographic keys stored alongside the data they protect
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
Provide artifacts for additional data origin authentication and integrity verification (DNSSEC) for child zones; FedRAMP requires DNSSEC.
- Control implementation statement for SC-20 citing the system mission and inheritance from common controls
- Denial of service protection configuration and capacity test results
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Cryptographic keys stored alongside the data they protect
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
Request and perform data origin authentication and data integrity verification on name/address resolution responses; DNSSEC validation.
- Control implementation statement for SC-21 citing the system mission and inheritance from common controls
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
Ensure DNS systems are fault-tolerant and implement role separation.
- Control implementation statement for SC-22 citing the system mission and inheritance from common controls
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
- Flat networks expose sensitive workloads without segmentation
Protect authenticity of communications sessions.
- Control implementation statement for SC-23 citing the system mission and inheritance from common controls
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
Protect confidentiality and integrity of FedRAMP-defined information at rest.
- Control implementation statement for SC-28 citing the system mission and inheritance from common controls
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Legacy TLS versions remain enabled on external services
- Flat networks expose sensitive workloads without segmentation
- Cryptographic keys stored alongside the data they protect
- Firewall rule base contains stale allow any entries
Implement cryptographic mechanisms to prevent unauthorized disclosure/modification of FedRAMP-defined information on FedRAMP-defined components; FIPS-validated.
- At-rest encryption attestation
- Backups unencrypted
Maintain separate execution domain for each executing system process.
- Control implementation statement for SC-39 citing the system mission and inheritance from common controls
- TLS configuration scan results across in scope endpoints
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Flat networks expose sensitive workloads without segmentation
- Cryptographic keys stored alongside the data they protect
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
Prevent unauthorized and unintended information transfer via shared system resources.
- Control implementation statement for SC-4 citing the system mission and inheritance from common controls
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Cryptographic keys stored alongside the data they protect
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
System Time Synchronization. Synchronize system clocks within and between systems and system components
- NTP topology
- Clock drift
System Time Synchronization | Synchronization with Authoritative Time Source. (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and (b) Synchronize the internal system clocks to the authoritative
- NTP authoritative source
- Public NTP only
Protect against or limit effects of DoS attacks using FedRAMP-defined safeguards.
- Control implementation statement for SC-5 citing the system mission and inheritance from common controls
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Cryptographic keys stored alongside the data they protect
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
Monitor/control communications at external boundary and key internal boundaries; implement subnetworks for publicly accessible components.
- Control implementation statement for SC-7 citing the system mission and inheritance from common controls
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components]
- Host firewall config
- Host firewall off
Boundary Protection | Fail Secure. Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device
- Fail-closed config
- Fail open
Limit number of external network connections to system; TIC-aligned.
- TIC/managed connections
- Multiple uncontrolled gateways
Implement managed interface for each external telecommunications service; establish traffic flow policy; protect confidentiality and integrity; document exceptions; review at least annually.
- Telecom interface inventory
- Unmanaged services
Deny network communications by default; allow by exception.
- Default deny rule
- Permissive rules
Prevent split tunneling for remote devices unless securely provisioned.
- VPN client policy
- Split tunneling enabled
Route internal traffic to FedRAMP-defined external networks through authenticated proxies.
- Proxy config
- Direct egress
Protect confidentiality and integrity of transmitted information using cryptographic mechanisms.
- Control implementation statement for SC-8 citing the system mission and inheritance from common controls
- Denial of service protection configuration and capacity test results
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
- Flat networks expose sensitive workloads without segmentation
Implement FIPS-validated cryptographic mechanisms to prevent unauthorized disclosure and detect changes during transmission.
- FIPS 140 cert numbers
- TLS scan
- TLS 1.0/1.1 enabled
SI - System and Information Integrity
Develop and review system/information integrity policy at least annually.
- Control implementation statement for SI-1 citing the system mission and inheritance from common controls
- Input validation standards and code review checklist
- Security monitoring alert tuning records
- Patch management policy with severity based SLAs
- Patch deployment reports across server, endpoint, and network estates
- Input validation handled inconsistently across microservices
- Alert backlog exceeds analyst capacity leading to triage delays
- Critical patches deployed beyond the policy SLA without exception
Check validity of FedRAMP-defined information inputs.
- Control implementation statement for SI-10 citing the system mission and inheritance from common controls
- Input validation standards and code review checklist
- Security monitoring alert tuning records
- Patch management policy with severity based SLAs
- Patch deployment reports across server, endpoint, and network estates
- Alert backlog exceeds analyst capacity leading to triage delays
- Critical patches deployed beyond the policy SLA without exception
- EDR coverage gaps on legacy operating systems
Generate error messages providing necessary info without revealing sensitive info; reveal only to authorized.
- Error handling review
- Stack traces exposed
Manage and retain information consistent with applicable laws, regulations, policies, standards.
- Control implementation statement for SI-12 citing the system mission and inheritance from common controls
- Patch management policy with severity based SLAs
- Patch deployment reports across server, endpoint, and network estates
- Endpoint detection and response coverage report
- Vulnerability remediation tickets with verification screenshots
- Critical patches deployed beyond the policy SLA without exception
- EDR coverage gaps on legacy operating systems
- Anti malware signatures not updated on isolated network segments
Implement FedRAMP-defined safeguards to protect memory from unauthorized code execution (DEP, ASLR).
- Control implementation statement for SI-16 citing the system mission and inheritance from common controls
- Input validation standards and code review checklist
- Security monitoring alert tuning records
- Patch management policy with severity based SLAs
- Patch deployment reports across server, endpoint, and network estates
- EDR coverage gaps on legacy operating systems
- Anti malware signatures not updated on isolated network segments
- Input validation handled inconsistently across microservices
Identify, report, and correct system flaws; remediate within FedRAMP-defined timeframes (HIGH critical 15d, high 30d).
- Control implementation statement for SI-2 citing the system mission and inheritance from common controls
- Security monitoring alert tuning records
- Patch management policy with severity based SLAs
- Patch deployment reports across server, endpoint, and network estates
- Endpoint detection and response coverage report
- Vulnerability remediation tickets with verification screenshots
- Input validation handled inconsistently across microservices
- Alert backlog exceeds analyst capacity leading to triage delays
- Critical patches deployed beyond the policy SLA without exception
- EDR coverage gaps on legacy operating systems
Determine status of flaw remediation via automated mechanisms at FedRAMP-defined frequency (at least monthly).
- Patch status dashboard
- Manual reporting
Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined
- MTTR metrics
- No MTTR tracking
Implement signature-based and non-signature-based malicious code protection; configure to scan endpoints and entry/exit points.
- Control implementation statement for SI-3 citing the system mission and inheritance from common controls
- Patch management policy with severity based SLAs
- Patch deployment reports across server, endpoint, and network estates
- Endpoint detection and response coverage report
- Vulnerability remediation tickets with verification screenshots
- Alert backlog exceeds analyst capacity leading to triage delays
- Critical patches deployed beyond the policy SLA without exception
- EDR coverage gaps on legacy operating systems
Monitor system to detect attacks; identify unauthorized use; deploy monitoring devices at boundaries and key internal points.
- Control implementation statement for SI-4 citing the system mission and inheritance from common controls
- Patch deployment reports across server, endpoint, and network estates
- Endpoint detection and response coverage report
- Vulnerability remediation tickets with verification screenshots
- Input validation standards and code review checklist
- Security monitoring alert tuning records
- Alert backlog exceeds analyst capacity leading to triage delays
- Critical patches deployed beyond the policy SLA without exception
- EDR coverage gaps on legacy operating systems
- Anti malware signatures not updated on isolated network segments
System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system
- IDS architecture
- Siloed IDS
System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system
- SIEM correlation
- Siloed monitoring
System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points
- DNS tunneling detection
- No covert channel detection
Employ automated tools to support near-real-time analysis of events.
- SIEM correlation
- Batch analysis only
System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms]
- EDR coverage
- EDR gaps
Determine criteria for unusual or unauthorized activity; monitor inbound/outbound communications.
- Egress monitoring
- No egress monitoring
Alert FedRAMP-defined personnel when indications of compromise/potential compromise occur.
- Alert rules
- On-call rotation
- No on-call
Receive alerts/advisories/directives from FedRAMP-defined external organizations (US-CERT, CISA); generate internal; disseminate.
- Control implementation statement for SI-5 citing the system mission and inheritance from common controls
- Endpoint detection and response coverage report
- Vulnerability remediation tickets with verification screenshots
- Input validation standards and code review checklist
- Security monitoring alert tuning records
- Alert backlog exceeds analyst capacity leading to triage delays
- Critical patches deployed beyond the policy SLA without exception
- EDR coverage gaps on legacy operating systems
Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system
- Function verification logs
- No verification
Employ integrity verification tools to detect unauthorized changes to software, firmware, information; HIGH only.
- Control implementation statement for SI-7 citing the system mission and inheritance from common controls
- Input validation standards and code review checklist
- Security monitoring alert tuning records
- Patch management policy with severity based SLAs
- Patch deployment reports across server, endpoint, and network estates
- Critical patches deployed beyond the policy SLA without exception
- EDR coverage gaps on legacy operating systems
- Anti malware signatures not updated on isolated network segments
Perform integrity checks of software, firmware, information at FedRAMP-defined frequency or trigger events.
- Integrity check schedule
- Infrequent checks
Incorporate detection of FedRAMP-defined unauthorized changes into IR capability.
- IR playbook for FIM
- FIM not in IR
Employ spam protection at entry/exit points; update spam protection mechanisms when new releases available.
- Email gateway config
- No spam protection
Spam Protection | Automatic Updates. Automatically update spam protection mechanisms [Assignment: organization-defined frequency]
- Auto-update config
- Manual updates
SR - Supply Chain Risk Management
Develop, document, disseminate, and review supply chain risk management policy and procedures at defined frequency.
- Control implementation statement for SR-1 citing the system mission and inheritance from common controls
- Tiered vendor inventory with criticality scoring
- Component authenticity verification evidence for hardware purchases
- Continuous monitoring scorecards for critical suppliers
- Contractual flow down of security requirements to subcontractors
- Supplier incident notification clauses and exercise records
- Vendor risk tier ratings static despite changes in service scope
- Counterfeit detection procedures absent for hardware refresh cycles
- Supplier incidents discovered through news rather than contractual notification
- Flow down clauses present in master agreements but missing from statements of work
Inspect systems or components at defined frequency or upon indications of tampering to detect compromise.
- Control implementation statement for SR-10 citing the system mission and inheritance from common controls
- Tiered vendor inventory with criticality scoring
- Component authenticity verification evidence for hardware purchases
- Continuous monitoring scorecards for critical suppliers
- Contractual flow down of security requirements to subcontractors
- Supplier incident notification clauses and exercise records
- Counterfeit detection procedures absent for hardware refresh cycles
- Supplier incidents discovered through news rather than contractual notification
- Flow down clauses present in master agreements but missing from statements of work
- Sub tier suppliers not identified for critical components
Implement anti-counterfeit policy and procedures to detect and prevent counterfeit components.
- Control implementation statement for SR-11 citing the system mission and inheritance from common controls
- Component authenticity verification evidence for hardware purchases
- Continuous monitoring scorecards for critical suppliers
- Contractual flow down of security requirements to subcontractors
- Supplier incident notification clauses and exercise records
- Counterfeit detection procedures absent for hardware refresh cycles
- Supplier incidents discovered through news rather than contractual notification
- Flow down clauses present in master agreements but missing from statements of work
Component Authenticity | Anti-counterfeit Training. Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware)
- Training curriculum
- Training records
- LMS records
- No role-based training
Component Authenticity | Configuration Control for Component Service and Repair. Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system
- Repair handling procedure
- Asset transit logs
- Asset tracker
- No revalidation after repair
Dispose of data, documentation, tools, or system components using defined techniques and methods.
- Control implementation statement for SR-12 citing the system mission and inheritance from common controls
- Continuous monitoring scorecards for critical suppliers
- Contractual flow down of security requirements to subcontractors
- Supplier incident notification clauses and exercise records
- Supply chain risk management policy and program charter
- Tiered vendor inventory with criticality scoring
- Supplier incidents discovered through news rather than contractual notification
- Flow down clauses present in master agreements but missing from statements of work
- Sub tier suppliers not identified for critical components
- Vendor risk tier ratings static despite changes in service scope
Develop a C-SCRM plan for managing supply chain risks for systems, components, and services; review and update at defined frequency.
- Control implementation statement for SR-2 citing the system mission and inheritance from common controls
- Component authenticity verification evidence for hardware purchases
- Continuous monitoring scorecards for critical suppliers
- Contractual flow down of security requirements to subcontractors
- Supplier incident notification clauses and exercise records
- Vendor risk tier ratings static despite changes in service scope
- Counterfeit detection procedures absent for hardware refresh cycles
- Supplier incidents discovered through news rather than contractual notification
Supply Chain Risk Management Plan | Establish SCRM Team. Establish a supply chain risk management team consisting of [Assignment: organization-defined personnel, roles, and responsibilities] to lead and support the following SCRM activities: [Assignment: organization-defined
- Team charter
- Roster
- Meeting minutes
- Collaboration site
- No legal or procurement reps
Establish processes to identify, protect, detect, respond, and recover across the supply chain lifecycle.
- Control implementation statement for SR-3 citing the system mission and inheritance from common controls
- Continuous monitoring scorecards for critical suppliers
- Contractual flow down of security requirements to subcontractors
- Supplier incident notification clauses and exercise records
- Supply chain risk management policy and program charter
- Tiered vendor inventory with criticality scoring
- Counterfeit detection procedures absent for hardware refresh cycles
- Supplier incidents discovered through news rather than contractual notification
- Flow down clauses present in master agreements but missing from statements of work
- Sub tier suppliers not identified for critical components
Employ acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks.
- Control implementation statement for SR-5 citing the system mission and inheritance from common controls
- Supplier incident notification clauses and exercise records
- Supply chain risk management policy and program charter
- Tiered vendor inventory with criticality scoring
- Component authenticity verification evidence for hardware purchases
- Continuous monitoring scorecards for critical suppliers
- Counterfeit detection procedures absent for hardware refresh cycles
- Supplier incidents discovered through news rather than contractual notification
- Flow down clauses present in master agreements but missing from statements of work
- Sub tier suppliers not identified for critical components
Assess and review the supply chain risk posture of suppliers at defined frequency and after significant events.
- Control implementation statement for SR-6 citing the system mission and inheritance from common controls
- Supply chain risk management policy and program charter
- Tiered vendor inventory with criticality scoring
- Component authenticity verification evidence for hardware purchases
- Continuous monitoring scorecards for critical suppliers
- Supplier incidents discovered through news rather than contractual notification
- Flow down clauses present in master agreements but missing from statements of work
- Sub tier suppliers not identified for critical components
Establish agreements with suppliers for notification of supply chain compromises and relevant changes.
- Control implementation statement for SR-8 citing the system mission and inheritance from common controls
- Component authenticity verification evidence for hardware purchases
- Continuous monitoring scorecards for critical suppliers
- Contractual flow down of security requirements to subcontractors
- Supplier incident notification clauses and exercise records
- Supplier incidents discovered through news rather than contractual notification
- Flow down clauses present in master agreements but missing from statements of work
- Sub tier suppliers not identified for critical components
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FedRAMP Moderate framework page.