NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
System Protection and Communications
Assess implementation of boundary protections to monitor and control communications at external system boundaries.
- FedRAMP SSP control implementation narrative for 3.13.1 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing 3.13.1 scope across data, control, and management planes for the cloud service offering
- Trusted Internet Connection (TIC) alignment evidence including managed interface inventory
- Web application firewall and DDoS protection configuration screenshots
- Deny by default egress filtering rules with documented exceptions
- Managed interface inventory missing recently added SaaS interconnection
- Egress filtering set to permit by default with broad exception
- Web application firewall in detect only mode for production
Develop, document, and disseminate configuration management policy per FedRAMP parameters.
- FedRAMP SSP control implementation narrative for FEDRAMP-CM-1 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing FEDRAMP-CM-1 scope across data, control, and management planes for the cloud service offering
- Approved policy document with annual review attestations from CISO or AO
- Procedures dissemination evidence to system owners and 3PAO with version control log
- FedRAMP control parameter table showing organization-defined values aligned to baseline
- Policy exists but not disseminated to all in scope roles per FedRAMP parameter
- Annual review attestation missing for two consecutive cycles
- FedRAMP parameter values left at NIST defaults instead of FedRAMP overlay
Develop, document, and maintain a current baseline configuration of the information system. FedRAMP requires CIS benchmark or equivalent.
- FedRAMP SSP control implementation narrative for FEDRAMP-CM-2 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing FEDRAMP-CM-2 scope across data, control, and management planes for the cloud service offering
- Hardened baseline configuration documents per CIS benchmark or DISA STIG with FedRAMP deviations
- Infrastructure as code repository commits showing baseline enforcement via Terraform or CloudFormation
- Baseline drift detection reports with remediation tickets
- Baseline drift undetected because compliance scanning omits new resource types
- Configuration exceptions registered but never reviewed for sunset
- Production hosts diverge from infrastructure as code baseline without change record
Establish and document configuration settings using security configuration checklists. FedRAMP defines specific security configuration requirements.
- FedRAMP SSP control implementation narrative for FEDRAMP-CM-6 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing FEDRAMP-CM-6 scope across data, control, and management planes for the cloud service offering
- Configuration settings library aligned to CIS or USGCB with FedRAMP parameter overlays
- Compliance scan results showing settings enforcement across production fleet
- Configuration exception register with risk acceptance signed by AO
- Baseline drift undetected because compliance scanning omits new resource types
- Configuration exceptions registered but never reviewed for sunset
- Production hosts diverge from infrastructure as code baseline without change record
Conduct backups of system-level, user-level, and system documentation information per FedRAMP-defined frequencies.
- FedRAMP SSP control implementation narrative for FEDRAMP-CP-9 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing FEDRAMP-CP-9 scope across data, control, and management planes for the cloud service offering
- Backup schedule documentation meeting FedRAMP daily incremental and weekly full minimums
- Backup integrity test results with documented restore validation per quarter
- Geographically separated backup storage attestation with encryption at rest evidence
- Restore tests run on schedule but only against non production environment
- Backup encryption keys colocated with backup storage region
- Documentation backup omitted, only data restore tested
Develop, document, and disseminate system and communications protection policy per FedRAMP parameters.
- FedRAMP SSP control implementation narrative for FEDRAMP-SC-1 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing FEDRAMP-SC-1 scope across data, control, and management planes for the cloud service offering
- Approved policy document with annual review attestations from CISO or AO
- Procedures dissemination evidence to system owners and 3PAO with version control log
- FedRAMP control parameter table showing organization-defined values aligned to baseline
- Policy exists but not disseminated to all in scope roles per FedRAMP parameter
- Annual review attestation missing for two consecutive cycles
- FedRAMP parameter values left at NIST defaults instead of FedRAMP overlay
Establish and manage cryptographic keys using NIST-approved key management technology and processes.
- FedRAMP SSP control implementation narrative for FEDRAMP-SC-12 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing FEDRAMP-SC-12 scope across data, control, and management planes for the cloud service offering
- Approved policy document with annual review attestations from CISO or AO
- Procedures dissemination evidence to system owners and 3PAO with version control log
- FedRAMP control parameter table showing organization-defined values aligned to baseline
- Non FIPS validated cryptographic library in scope for sensitive data
- Key rotation cadence undocumented for envelope encryption keys
- TLS 1.0 or 1.1 still permitted on internal east west traffic
Implement FIPS 140-2/140-3 validated cryptography to protect the confidentiality and integrity of information.
- FedRAMP SSP control implementation narrative for FEDRAMP-SC-13 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing FEDRAMP-SC-13 scope across data, control, and management planes for the cloud service offering
- Approved policy document with annual review attestations from CISO or AO
- Procedures dissemination evidence to system owners and 3PAO with version control log
- FedRAMP control parameter table showing organization-defined values aligned to baseline
- Non FIPS validated cryptographic library in scope for sensitive data
- Key rotation cadence undocumented for envelope encryption keys
- TLS 1.0 or 1.1 still permitted on internal east west traffic
Protect the confidentiality and integrity of information at rest. FedRAMP requires FIPS-validated encryption for all CUI/sensitive data at rest.
- FedRAMP SSP control implementation narrative for FEDRAMP-SC-28 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing FEDRAMP-SC-28 scope across data, control, and management planes for the cloud service offering
- Encryption at rest configuration evidence for object storage, block volumes, and databases using FIPS validated modules
- Tenant data isolation attestation including envelope encryption design
- Key custody segregation showing customer managed key option where applicable
- Managed interface inventory missing recently added SaaS interconnection
- Egress filtering set to permit by default with broad exception
- Web application firewall in detect only mode for production
Monitor and control communications at the external managed interfaces of the system and at key internal managed interfaces within the system.
- FedRAMP SSP control implementation narrative for FEDRAMP-SC-7 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing FEDRAMP-SC-7 scope across data, control, and management planes for the cloud service offering
- Trusted Internet Connection (TIC) alignment evidence including managed interface inventory
- Web application firewall and DDoS protection configuration screenshots
- Deny by default egress filtering rules with documented exceptions
- Managed interface inventory missing recently added SaaS interconnection
- Egress filtering set to permit by default with broad exception
- Web application firewall in detect only mode for production
Protect the confidentiality and integrity of transmitted information. FedRAMP requires FIPS-validated encryption for all data in transit.
- FedRAMP SSP control implementation narrative for FEDRAMP-SC-8 including FedRAMP parameter values and inheritance from leveraged authorizations
- Authorization boundary diagram showing FEDRAMP-SC-8 scope across data, control, and management planes for the cloud service offering
- TLS 1.2 minimum enforcement evidence with cipher suite hardening configuration
- Internal east west encryption attestation for service mesh or VPC traffic
- Certificate inventory with renewal automation and pinning policy
- Managed interface inventory missing recently added SaaS interconnection
- Egress filtering set to permit by default with broad exception
- Web application firewall in detect only mode for production
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements framework page.