Skip to content

Evidence request lists

NIST SP 800-53 Rev 5 MODERATE

Evidence request list. 275 controls, 275 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

AC Access Control

AC-1
Policy and Procedures

Develop and disseminate access control policy and procedures; review at least annually (FedRAMP parameter); update following defined events.

Artefacts an auditor will ask for
  • Control implementation statement for AC-1 citing the system mission and inheritance from common controls
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
Where this commonly fails
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
AC-11
Device Lock

Prevent further access by initiating device lock after 15 minutes inactivity (FedRAMP) or upon user request.

Artefacts an auditor will ask for
  • Control implementation statement for AC-11 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-11(1)
Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image

Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image

Artefacts an auditor will ask for
  • Lock screen image configuration
  • Screenshots showing pattern-hiding
  • MDM payload
Where this commonly fails
  • Lock shows live data
  • Configuration drift
  • No screenshot evidence
AC-12
Session Termination

Automatically terminate user session after FedRAMP-defined conditions (idle timeout, trigger events).

Artefacts an auditor will ask for
  • Control implementation statement for AC-12 citing the system mission and inheritance from common controls
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-14
Permitted Actions Without Identification or Authentication

Identify and document actions allowed without identification or authentication.

Artefacts an auditor will ask for
  • Control implementation statement for AC-14 citing the system mission and inheritance from common controls
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-17
Remote Access

Establish usage restrictions, configuration requirements, and authorize remote access prior to allowing.

Artefacts an auditor will ask for
  • Control implementation statement for AC-17 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
AC-17(1)
Monitoring and Control

Employ automated mechanisms to monitor and control remote access.

Artefacts an auditor will ask for
  • VPN logs
  • Remote session monitoring
Where this commonly fails
  • No remote session logging
AC-17(2)
Protection of Confidentiality and Integrity Using Encryption

Implement cryptographic mechanisms to protect remote access sessions; FIPS-validated.

Artefacts an auditor will ask for
  • FIPS 140 module list
  • TLS config
Where this commonly fails
  • Non-FIPS ciphers enabled
AC-17(3)
Managed Access Control Points

Route remote accesses through FedRAMP-defined number of managed network access control points.

Artefacts an auditor will ask for
  • Network ingress diagram
  • TIC compliance
Where this commonly fails
  • Split tunneling allowed
AC-17(4)
Privileged Commands and Access

Authorize execution of privileged commands and access to security-relevant information via remote access only for defined needs.

Artefacts an auditor will ask for
  • Bastion logs
  • Approved command list
Where this commonly fails
  • No bastion enforcement
AC-18
Wireless Access

Establish configuration requirements, usage restrictions, authorize wireless access.

Artefacts an auditor will ask for
  • Control implementation statement for AC-18 citing the system mission and inheritance from common controls
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
AC-18(1)
Authentication and Encryption

Protect wireless access using authentication and encryption (WPA2/3 Enterprise minimum).

Artefacts an auditor will ask for
  • WPA3 config
  • RADIUS records
Where this commonly fails
  • PSK in use
AC-18(3)
Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment

Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment

Artefacts an auditor will ask for
  • MDM policy
Where this commonly fails
  • Bluetooth/Wi-Fi enabled by default
AC-19
Access Control for Mobile Devices

Establish configuration requirements and usage restrictions for mobile devices.

Artefacts an auditor will ask for
  • Control implementation statement for AC-19 citing the system mission and inheritance from common controls
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
AC-19(5)
Full Device or Container-Based Encryption

Employ full device or container-based encryption on mobile devices.

Artefacts an auditor will ask for
  • Encryption attestation
Where this commonly fails
  • Personal containers unencrypted
AC-2
Account Management

Manage accounts; review at least monthly for privileged, every six months for non-privileged (FedRAMP); notify within FedRAMP-defined timeframes on changes.

Artefacts an auditor will ask for
  • Control implementation statement for AC-2 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
AC-2(1)
Automated System Account Management

Support account management via automated mechanisms; required at HIGH baseline.

Artefacts an auditor will ask for
  • IDP configuration
  • Workflow automation evidence
  • SCIM provisioning logs
Where this commonly fails
  • Manual ticket-only provisioning
  • No automated deprovisioning
AC-2(13)
Disable Accounts for High-Risk Individuals

Disable accounts of users posing significant risk within FedRAMP-defined timeframe (1 hour).

Artefacts an auditor will ask for
  • Insider threat workflow
  • 1-hour disable evidence
Where this commonly fails
  • No coordination with HR/legal
AC-2(2)
Automated Temporary and Emergency Account Management

Automatically disable temporary and emergency accounts within FedRAMP-defined timeframe (no longer than 24 hours).

Artefacts an auditor will ask for
  • Temp account expiry logs
  • Automation script
  • JIT access records
Where this commonly fails
  • No automated expiry
  • Emergency accounts persist
AC-2(3)
Disable Accounts

Disable accounts within FedRAMP-defined timeframe when no longer required, terminated, or inactive (35 days inactive).

Artefacts an auditor will ask for
  • Inactivity disable logs
  • HR-IAM integration
  • 35-day report
Where this commonly fails
  • Inactive accounts active over 35 days
AC-2(4)
Automated Audit Actions

Automatically audit account creation, modification, enabling, disabling, removal; notify defined personnel.

Artefacts an auditor will ask for
  • Account change audit logs
  • Alerting rules
Where this commonly fails
  • No alerts on account changes
AC-2(5)
Inactivity Logout

Require users to log out when inactivity exceeds FedRAMP-defined period (15 minutes for non-mobile, 30 for mobile).

Artefacts an auditor will ask for
  • Session timeout config
  • Policy baseline
Where this commonly fails
  • Timeout over 15 minutes
AC-20
Use of External Systems

Establish terms and conditions for use of external systems; prohibit unless authorized.

Artefacts an auditor will ask for
  • Control implementation statement for AC-20 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-20(1)
Limits on Authorized Use

Permit use of external systems only after verifying security/privacy controls or approved connection agreement.

Artefacts an auditor will ask for
  • Interconnection agreements
  • Vendor assessments
Where this commonly fails
  • Missing ISA
AC-20(2)
Portable Storage Devices Restricted Use

Restrict use of organization-controlled portable storage on external systems.

Artefacts an auditor will ask for
  • USB control policy
  • DLP rules
Where this commonly fails
  • USB unrestricted
AC-21
Information Sharing

Enable authorized users to determine whether access authorizations match sharing restrictions.

Artefacts an auditor will ask for
  • Sharing policy
  • Classification labels
Where this commonly fails
  • No sharing review process
AC-22
Publicly Accessible Content

Designate users authorized to post; train them; review content quarterly for nonpublic information.

Artefacts an auditor will ask for
  • Control implementation statement for AC-22 citing the system mission and inheritance from common controls
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
AC-3
Access Enforcement

Enforce approved authorizations for logical access in accordance with policy.

Artefacts an auditor will ask for
  • Control implementation statement for AC-3 citing the system mission and inheritance from common controls
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
AC-4
Information Flow Enforcement

Enforce approved information flow control policies between connected systems and within the system.

Artefacts an auditor will ask for
  • Control implementation statement for AC-4 citing the system mission and inheritance from common controls
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-5
Separation of Duties

Identify and document duties requiring separation; define access authorizations to support.

Artefacts an auditor will ask for
  • Control implementation statement for AC-5 citing the system mission and inheritance from common controls
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
Where this commonly fails
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
AC-6
Least Privilege

Employ least privilege; allow only authorized access necessary to accomplish assigned tasks.

Artefacts an auditor will ask for
  • Control implementation statement for AC-6 citing the system mission and inheritance from common controls
  • Quarterly privileged access review attestations
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
AC-6(1)
Authorize Access to Security Functions

Authorize access for FedRAMP-defined personnel to security functions and security-relevant information.

Artefacts an auditor will ask for
  • Security admin role list
  • Approval records
Where this commonly fails
  • Undocumented sec-admin access
AC-6(10)
Prohibit Non-Privileged Users from Executing Privileged Functions

Prevent non-privileged users from executing privileged functions.

Artefacts an auditor will ask for
  • LPE prevention controls
  • EDR config
Where this commonly fails
  • Setuid binaries unaudited
AC-6(2)
Non-Privileged Access for Nonsecurity Functions

Require privileged users to use non-privileged accounts for nonsecurity functions.

Artefacts an auditor will ask for
  • Dual-account policy
  • Browse-as-user evidence
Where this commonly fails
  • Admins browse with admin
AC-6(5)
Privileged Accounts

Restrict privileged accounts to FedRAMP-defined personnel or roles.

Artefacts an auditor will ask for
  • Privileged role list
  • Quarterly review
Where this commonly fails
  • No periodic review
AC-6(7)
Review of User Privileges

Review privileges at least quarterly (FedRAMP) and reassign or remove as needed.

Artefacts an auditor will ask for
  • Quarterly privilege review
  • Remediation tickets
Where this commonly fails
  • Annual-only review
AC-6(9)
Log Use of Privileged Functions

Log execution of privileged functions.

Artefacts an auditor will ask for
  • Sudo logs
  • PAM session recording
Where this commonly fails
  • No PAM session logs
AC-7
Unsuccessful Logon Attempts

Enforce limit of 3 consecutive invalid logon attempts within 15 minutes (FedRAMP); lock for 30 min or until released.

Artefacts an auditor will ask for
  • Control implementation statement for AC-7 citing the system mission and inheritance from common controls
  • System access request forms with business justification
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
Where this commonly fails
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
  • Service accounts excluded from periodic recertification
AC-8
System Use Notification

Display approved system use notification/banner before granting access; FedRAMP requires specific language.

Artefacts an auditor will ask for
  • Login banner screenshot
  • Banner text
Where this commonly fails
  • Missing FedRAMP banner language

AT Awareness and Training

AT-1
Policy and Procedures

Develop, disseminate, and review awareness and training policy and procedures at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for AT-1 citing the system mission and inheritance from common controls
  • Insider threat awareness briefing materials
  • Training records retained in the learning management system
  • Attestation records signed at onboarding and annually
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
Where this commonly fails
  • Contractors and third parties not enrolled in mandatory training
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
  • Training content not reviewed annually for current threat trends
AT-2
Literacy Training and Awareness

Provide security awareness training within FedRAMP-defined timeframe of onboarding, on system change, and at least annually thereafter.

Artefacts an auditor will ask for
  • Control implementation statement for AT-2 citing the system mission and inheritance from common controls
  • Training records retained in the learning management system
  • Attestation records signed at onboarding and annually
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
Where this commonly fails
  • Contractors and third parties not enrolled in mandatory training
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
AT-2(2)
Insider Threat

Include insider threat recognition and reporting in awareness training.

Artefacts an auditor will ask for
  • Insider threat module
Where this commonly fails
  • Module absent
AT-2(3)
Social Engineering and Mining

Include social engineering and social mining recognition in training.

Artefacts an auditor will ask for
  • Phishing simulation results
Where this commonly fails
  • No phishing tests
AT-3
Role-Based Training

Provide role-based security training to personnel with significant security responsibilities before authorizing access and annually.

Artefacts an auditor will ask for
  • Control implementation statement for AT-3 citing the system mission and inheritance from common controls
  • Attestation records signed at onboarding and annually
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
  • Phishing simulation results with click and reporting rates
  • Insider threat awareness briefing materials
Where this commonly fails
  • Contractors and third parties not enrolled in mandatory training
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
  • Training content not reviewed annually for current threat trends
AT-4
Training Records

Document and monitor security training; retain records for FedRAMP-defined period (5 years).

Artefacts an auditor will ask for
  • Control implementation statement for AT-4 citing the system mission and inheritance from common controls
  • Annual security awareness training curriculum and completion roster
  • Role based training plan for privileged users and developers
  • Phishing simulation results with click and reporting rates
  • Insider threat awareness briefing materials
Where this commonly fails
  • Role based training not refreshed when job duties change
  • Phishing failures not followed by remedial coaching
  • Training content not reviewed annually for current threat trends

AU Audit and Accountability

AU-1
Policy and Procedures

Develop and review audit/accountability policy annually.

Artefacts an auditor will ask for
  • Control implementation statement for AU-1 citing the system mission and inheritance from common controls
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
Where this commonly fails
  • Audit log retention shorter than the policy mandated period
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
AU-11
Audit Record Retention

Retain audit records for at least one year (FedRAMP minimum) with 90 days immediately accessible online.

Artefacts an auditor will ask for
  • Control implementation statement for AU-11 citing the system mission and inheritance from common controls
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-12
Audit Record Generation

Provide audit record generation capability on all system components specified in AU-2.

Artefacts an auditor will ask for
  • Control implementation statement for AU-12 citing the system mission and inheritance from common controls
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-2
Event Logging

Identify event types selected for logging including FedRAMP minimum list; review and update at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for AU-2 citing the system mission and inheritance from common controls
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Audit log retention shorter than the policy mandated period
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
AU-3
Content of Audit Records

Audit records must contain: type, when, where, source, outcome, identity associated.

Artefacts an auditor will ask for
  • Control implementation statement for AU-3 citing the system mission and inheritance from common controls
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
AU-3(1)
Additional Audit Information

Generate audit records containing FedRAMP-defined additional information (session, host, full text of executed commands).

Artefacts an auditor will ask for
  • Enriched log sample
Where this commonly fails
  • Command text not captured
AU-4
Audit Log Storage Capacity

Allocate audit log storage capacity to accommodate FedRAMP-defined retention period.

Artefacts an auditor will ask for
  • Control implementation statement for AU-4 citing the system mission and inheritance from common controls
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-5
Response to Audit Logging Process Failures

Alert defined personnel on audit failure within FedRAMP timeframe; take defined action (overwrite oldest, shutdown, stop processing).

Artefacts an auditor will ask for
  • Control implementation statement for AU-5 citing the system mission and inheritance from common controls
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
Where this commonly fails
  • Reviewers acknowledge alerts but do not document investigation outcomes
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
AU-6
Audit Record Review, Analysis, and Reporting

Review and analyze audit records at least weekly (FedRAMP); report findings to defined personnel.

Artefacts an auditor will ask for
  • Control implementation statement for AU-6 citing the system mission and inheritance from common controls
  • Log review procedures with assigned analyst owners
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
  • Audit log retention shorter than the policy mandated period
AU-6(1)
Automated Process Integration

Integrate audit review with automated mechanisms (SIEM).

Artefacts an auditor will ask for
  • SIEM screenshot
Where this commonly fails
  • No SIEM
AU-6(3)
Correlate Audit Record Repositories

Analyze and correlate audit records across different repositories.

Artefacts an auditor will ask for
  • SIEM correlation rules
Where this commonly fails
  • Siloed logs
AU-7
Audit Record Reduction and Report Generation

Provide capability for audit record reduction and on-demand report generation.

Artefacts an auditor will ask for
  • Control implementation statement for AU-7 citing the system mission and inheritance from common controls
  • Time synchronisation evidence across logging endpoints
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
AU-7(1)
Automatic Processing

Process audit records for events of interest based on defined criteria.

Artefacts an auditor will ask for
  • SIEM use cases
Where this commonly fails
  • No detection rules
AU-8
Time Stamps

Use internal system clocks; record timestamps with FedRAMP-defined granularity (1 second), UTC or known offset.

Artefacts an auditor will ask for
  • Control implementation statement for AU-8 citing the system mission and inheritance from common controls
  • Audit log integrity controls including write once storage or hashing
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Clock drift across hosts breaks event correlation
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
  • Audit log retention shorter than the policy mandated period
AU-9
Protection of Audit Information

Protect audit information and tools from unauthorized access, modification, deletion.

Artefacts an auditor will ask for
  • Control implementation statement for AU-9 citing the system mission and inheritance from common controls
  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • SIEM ingestion configuration showing all in scope systems
  • Log review procedures with assigned analyst owners
Where this commonly fails
  • Privileged user activity not isolated for independent review
  • Critical log sources missing from the SIEM with no detection coverage
  • Audit log retention shorter than the policy mandated period
AU-9(4)
Access by Subset of Privileged Users

Authorize access to audit functionality only to subset of privileged users.

Artefacts an auditor will ask for
  • SIEM role list
Where this commonly fails
  • All admins see all logs

CA Assessment, Authorization, and Monitoring

CA-1
Policy and Procedures

Develop and review assessment/authorization policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for CA-1 citing the system mission and inheritance from common controls
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
Where this commonly fails
  • Authorization boundary description does not match the asset inventory
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
CA-2
Control Assessments

Assess controls annually (FedRAMP); third-party assessor (3PAO) required; produce SAR.

Artefacts an auditor will ask for
  • Control implementation statement for CA-2 citing the system mission and inheritance from common controls
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • Authorization boundary description does not match the asset inventory
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
CA-2(1)
Independent Assessors

Employ independent assessors; FedRAMP-accredited 3PAO required.

Artefacts an auditor will ask for
  • 3PAO accreditation
  • Independence statement
Where this commonly fails
  • Non-accredited assessor
CA-3
Information Exchange

Approve and manage exchange of information with external systems using ISA, MOU, contract; review annually.

Artefacts an auditor will ask for
  • Control implementation statement for CA-3 citing the system mission and inheritance from common controls
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
CA-5
Plan of Action and Milestones

Develop POAM; update at least monthly (FedRAMP); track remediation timelines (HIGH 30 days, MOD 90).

Artefacts an auditor will ask for
  • Control implementation statement for CA-5 citing the system mission and inheritance from common controls
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
Where this commonly fails
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
CA-6
Authorization

Senior official authorizes system; reauthorize every three years or upon significant change.

Artefacts an auditor will ask for
  • Control implementation statement for CA-6 citing the system mission and inheritance from common controls
  • Authorization to operate memorandum signed by the authorizing official
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
Where this commonly fails
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
  • Authorization boundary description does not match the asset inventory
CA-7
Continuous Monitoring

Establish continuous monitoring strategy with FedRAMP-defined metrics, monitoring frequencies, ongoing assessments.

Artefacts an auditor will ask for
  • Control implementation statement for CA-7 citing the system mission and inheritance from common controls
  • Continuous monitoring strategy with metric definitions
  • Independent assessor statement of independence
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
Where this commonly fails
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
CA-7(1)
Independent Assessment

Employ independent assessors for ongoing monitoring; FedRAMP 3PAO annual.

Artefacts an auditor will ask for
  • 3PAO ConMon engagement
Where this commonly fails
  • No independent ConMon
CA-7(4)
Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring

Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring

Artefacts an auditor will ask for
  • Risk monitoring procedure
  • Risk register
  • Change-driven re-assessments
Where this commonly fails
  • Risk monitoring siloed
  • No change triggers
  • Register stale
CA-9
Internal System Connections

Authorize internal connections of components to system; document interface characteristics.

Artefacts an auditor will ask for
  • Control implementation statement for CA-9 citing the system mission and inheritance from common controls
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where this commonly fails
  • Assessment scope omits inherited cloud provider controls
  • Reauthorization scheduled past the policy required interval
  • Authorization boundary description does not match the asset inventory

CM Configuration Management

CM-1
Policy and Procedures

Develop and review configuration management policy annually.

Artefacts an auditor will ask for
  • Control implementation statement for CM-1 citing the system mission and inheritance from common controls
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Asset inventory missing cloud workloads and ephemeral resources
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
CM-10
Software Usage Restrictions

Use software in accordance with contracts and copyright laws; track licenses; document peer-to-peer file sharing controls.

Artefacts an auditor will ask for
  • Control implementation statement for CM-10 citing the system mission and inheritance from common controls
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-11
User-Installed Software

Establish policies governing installation of software by users; enforce; monitor compliance.

Artefacts an auditor will ask for
  • Control implementation statement for CM-11 citing the system mission and inheritance from common controls
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
CM-12
Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is processed and stored; b. Identify and document the users who have access

Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is processed and stored; b. Identify and document the users who have access

Artefacts an auditor will ask for
  • Data location map
Where this commonly fails
  • No data inventory
CM-12(1)
Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational

Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational

Artefacts an auditor will ask for
  • DLP/discovery tool
Where this commonly fails
  • No data discovery
CM-2
Baseline Configuration

Develop and maintain baseline configurations; review and update annually (FedRAMP) and when required.

Artefacts an auditor will ask for
  • Control implementation statement for CM-2 citing the system mission and inheritance from common controls
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Asset inventory missing cloud workloads and ephemeral resources
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-2(2)
Automation Support for Accuracy and Currency

Maintain baseline currency via automated mechanisms.

Artefacts an auditor will ask for
  • CMDB auto-discovery
Where this commonly fails
  • Manual CMDB
CM-2(3)
Retention of Previous Configurations

Retain FedRAMP-defined number of previous baseline configurations (3) to support rollback.

Artefacts an auditor will ask for
  • Snapshot history
Where this commonly fails
  • No rollback capability
CM-2(7)
Configure Systems and Components for High-Risk Areas

Issue systems/devices with FedRAMP-defined security safeguards to individuals traveling to high-risk locations.

Artefacts an auditor will ask for
  • Travel laptop policy
Where this commonly fails
  • No travel device program
CM-3
Configuration Change Control

Determine, document, and approve changes; track, review, audit; CAB or equivalent; analyze security impact.

Artefacts an auditor will ask for
  • Control implementation statement for CM-3 citing the system mission and inheritance from common controls
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-3(2)
Testing, Validation, and Documentation of Changes

Test, validate, and document changes before implementing on operational system.

Artefacts an auditor will ask for
  • Test plan
  • Validation results
Where this commonly fails
  • No pre-prod testing
CM-3(4)
Security and Privacy Representatives

Require security and privacy representatives on change board for FedRAMP-defined configuration changes.

Artefacts an auditor will ask for
  • CAB roster
Where this commonly fails
  • No security on CAB
CM-4
Impact Analyses

Analyze changes to determine potential security/privacy impacts.

Artefacts an auditor will ask for
  • Control implementation statement for CM-4 citing the system mission and inheritance from common controls
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
CM-4(2)
Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements

Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements

Artefacts an auditor will ask for
  • Post-change verification reports
  • Control testing results
  • Tickets linking change to verification
Where this commonly fails
  • No post-change testing
  • Verification not documented
  • Controls drift after change
CM-5
Access Restrictions for Change

Define, document, approve, enforce physical and logical access restrictions for changes.

Artefacts an auditor will ask for
  • Control implementation statement for CM-5 citing the system mission and inheritance from common controls
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
Where this commonly fails
  • Baselines exist on paper but production hosts drift without alerting
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
CM-6
Configuration Settings

Establish/document configuration settings using checklists; CIS/USGCB/DISA STIG when available; HIGH baseline.

Artefacts an auditor will ask for
  • Control implementation statement for CM-6 citing the system mission and inheritance from common controls
  • Configuration drift detection reports from the CMDB or tooling
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
  • Asset inventory missing cloud workloads and ephemeral resources
CM-7
Least Functionality

Configure system to provide only essential capabilities; prohibit unnecessary functions, services, ports, protocols.

Artefacts an auditor will ask for
  • Control implementation statement for CM-7 citing the system mission and inheritance from common controls
  • Software inventory generated from authoritative discovery tooling
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
Where this commonly fails
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
CM-7(1)
Periodic Review

Review system functions, ports, protocols, services at least monthly (FedRAMP); disable as unnecessary.

Artefacts an auditor will ask for
  • Monthly review records
Where this commonly fails
  • Annual-only review
CM-7(2)
Prevent Program Execution

Prevent program execution according to FedRAMP-defined policies (rules of behavior).

Artefacts an auditor will ask for
  • App control policy
Where this commonly fails
  • No application control
CM-7(5)
Authorized Software Allow-by-Exception

Identify and maintain authorized software list; employ allowlist; review at least annually; HIGH requirement.

Artefacts an auditor will ask for
  • Allowlist policy
  • Annual review
Where this commonly fails
  • No allowlisting
CM-8
System Component Inventory

Develop and document inventory of system components; review and update at least monthly (FedRAMP).

Artefacts an auditor will ask for
  • Control implementation statement for CM-8 citing the system mission and inheritance from common controls
  • Emergency change records with retroactive approvals
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Emergency changes bypass CAB and lack retrospective review
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
  • Asset inventory missing cloud workloads and ephemeral resources
CM-8(1)
Updates During Installation and Removal

Update inventory as part of component installations, removals, updates.

Artefacts an auditor will ask for
  • Installation workflow
Where this commonly fails
  • Manual inventory
CM-8(3)
Automated Unauthorized Component Detection

Employ automated mechanisms to detect unauthorized components at FedRAMP-defined frequency; HIGH only continuous.

Artefacts an auditor will ask for
  • NAC alerts
  • Rogue device reports
Where this commonly fails
  • No rogue detection
CM-9
Configuration Management Plan

Develop, document, implement configuration management plan addressing roles, processes, items under CM, identification scheme.

Artefacts an auditor will ask for
  • Control implementation statement for CM-9 citing the system mission and inheritance from common controls
  • Configuration management policy and change control procedure
  • Approved baseline configurations for each platform family
  • Change advisory board minutes with risk assessments
  • Configuration drift detection reports from the CMDB or tooling
Where this commonly fails
  • Unauthorised software present on endpoints not flagged by tooling
  • Hardening benchmarks applied at build but not re evaluated annually
  • Asset inventory missing cloud workloads and ephemeral resources

CP Contingency Planning

CP-1
Policy and Procedures

Develop and review contingency planning policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for CP-1 citing the system mission and inheritance from common controls
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Backups taken but restore tests never performed end to end
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
CP-10
System Recovery and Reconstitution

Provide for recovery and reconstitution of system to known state within RTO.

Artefacts an auditor will ask for
  • Control implementation statement for CP-10 citing the system mission and inheritance from common controls
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-10(2)
System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based

System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based

Artefacts an auditor will ask for
  • DB transaction logs
Where this commonly fails
  • No transaction replay
CP-2
Contingency Plan

Develop contingency plan; review and update annually (FedRAMP); coordinate with related plans.

Artefacts an auditor will ask for
  • Control implementation statement for CP-2 citing the system mission and inheritance from common controls
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Backups taken but restore tests never performed end to end
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
CP-2(1)
Coordinate with Related Plans

Coordinate contingency plan with related plans (BCP, DRP, COOP, IRP).

Artefacts an auditor will ask for
  • Coordination matrix
Where this commonly fails
  • Siloed plans
CP-2(3)
Resume Mission and Business Functions

Plan for resumption of mission/business functions within FedRAMP-defined time period after contingency plan activation.

Artefacts an auditor will ask for
  • RTO documentation
Where this commonly fails
  • RTO undefined
CP-2(8)
Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions

Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions

Artefacts an auditor will ask for
  • BIA criticality map
Where this commonly fails
  • No criticality tiers
CP-3
Contingency Training

Provide contingency training to users assigned roles; within FedRAMP timeframe of role assignment and at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for CP-3 citing the system mission and inheritance from common controls
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
Where this commonly fails
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-4
Contingency Plan Testing

Test contingency plan at least annually (FedRAMP) using FedRAMP-defined tests; review test results.

Artefacts an auditor will ask for
  • Control implementation statement for CP-4 citing the system mission and inheritance from common controls
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
Where this commonly fails
  • RTO and RPO targets undefined for tier two systems
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
CP-4(1)
Coordinate with Related Plans

Coordinate contingency plan testing with related plan testing.

Artefacts an auditor will ask for
  • Joint test plan
Where this commonly fails
  • Independent testing only
CP-6
Alternate Storage Site

Establish alternate storage site with agreements to permit storage and retrieval of system backup information.

Artefacts an auditor will ask for
  • Control implementation statement for CP-6 citing the system mission and inheritance from common controls
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
Where this commonly fails
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-6(1)
Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats

Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats

Artefacts an auditor will ask for
  • Geographic separation evidence
Where this commonly fails
  • Same metro zone
CP-6(3)
Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions

Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions

Artefacts an auditor will ask for
  • Accessibility analysis
Where this commonly fails
  • No analysis
CP-7
Alternate Processing Site

Establish alternate processing site with agreements for resumption of operations within FedRAMP-defined RTO.

Artefacts an auditor will ask for
  • Control implementation statement for CP-7 citing the system mission and inheritance from common controls
  • Backup schedule, retention, and offsite or immutable copy evidence
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
  • Backups taken but restore tests never performed end to end
CP-7(1)
Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats

Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats

Artefacts an auditor will ask for
  • Geographic separation
Where this commonly fails
  • Same region
CP-7(2)
Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions

Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions

Artefacts an auditor will ask for
  • Accessibility plan
Where this commonly fails
  • No plan
CP-7(3)
Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives)

Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives)

Artefacts an auditor will ask for
  • SLA priority clause
Where this commonly fails
  • No priority clauses
CP-8
Telecommunications Services

Establish alternate telecommunications services with agreements to permit resumption of system operations.

Artefacts an auditor will ask for
  • Control implementation statement for CP-8 citing the system mission and inheritance from common controls
  • Annual tabletop and full failover test reports
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
Where this commonly fails
  • Tabletop exercises lack participation from business owners
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
CP-8(1)
Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and (b) Request Telecommunications Service Priority

Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and (b) Request Telecommunications Service Priority

Artefacts an auditor will ask for
  • TSP enrollment
Where this commonly fails
  • No TSP
CP-8(2)
Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services

Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services

Artefacts an auditor will ask for
  • Diverse routing
Where this commonly fails
  • SPOFs unmitigated
CP-9
System Backup

Conduct backups of user-level, system-level, and security-related documentation; FedRAMP-defined frequency (daily incremental, weekly full).

Artefacts an auditor will ask for
  • Control implementation statement for CP-9 citing the system mission and inheritance from common controls
  • Alternate processing site contract and capacity attestation
  • Restoration test logs with success criteria signed off
  • Business impact analysis identifying critical systems
  • Contingency plan with recovery time and recovery point objectives
  • Backup schedule, retention, and offsite or immutable copy evidence
Where this commonly fails
  • Alternate site capacity not validated against current load
  • Plan not updated after major architecture changes
  • Backups taken but restore tests never performed end to end
  • RTO and RPO targets undefined for tier two systems
CP-9(1)
Testing for Reliability and Integrity

Test backup information annually to verify reliability and integrity.

Artefacts an auditor will ask for
  • Restore test results
Where this commonly fails
  • Backups never restored
CP-9(8)
System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information]

System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information]

Artefacts an auditor will ask for
  • Backup encryption config
Where this commonly fails
  • Unencrypted backups

IA Identification and Authentication

IA-1
Policy and Procedures

Develop and review identification and authentication policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for IA-1 citing the system mission and inheritance from common controls
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
Where this commonly fails
  • Default vendor credentials remain on appliances and IoT devices
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
IA-11
Re-Authentication

Require re-authentication when FedRAMP-defined circumstances occur (role change, privilege change, time period elapsed).

Artefacts an auditor will ask for
  • Control implementation statement for IA-11 citing the system mission and inheritance from common controls
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-12
Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a

Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a

Artefacts an auditor will ask for
  • Control implementation statement for IA-12 citing the system mission and inheritance from common controls
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-2
Identification and Authentication (Organizational Users)

Uniquely identify and authenticate organizational users and associate identity with processes acting on behalf of users.

Artefacts an auditor will ask for
  • Control implementation statement for IA-2 citing the system mission and inheritance from common controls
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Default vendor credentials remain on appliances and IoT devices
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
IA-3
Device Identification and Authentication

Uniquely identify and authenticate devices before establishing connection.

Artefacts an auditor will ask for
  • Control implementation statement for IA-3 citing the system mission and inheritance from common controls
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
IA-4
Identifier Management

Manage identifiers; uniquely identify; prevent reuse for FedRAMP-defined period.

Artefacts an auditor will ask for
  • Control implementation statement for IA-4 citing the system mission and inheritance from common controls
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-5
Authenticator Management

Manage authenticators; verify identity prior to issuing; establish initial content; protect.

Artefacts an auditor will ask for
  • Control implementation statement for IA-5 citing the system mission and inheritance from common controls
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
Where this commonly fails
  • Password complexity enforced but reuse not blocked across systems
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
IA-6
Authentication Feedback

Obscure authentication feedback during authentication process.

Artefacts an auditor will ask for
  • Control implementation statement for IA-6 citing the system mission and inheritance from common controls
  • Service account credential vault inventory and rotation logs
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
  • Default vendor credentials remain on appliances and IoT devices
IA-7
Cryptographic Module Authentication

Implement authentication to cryptographic modules meeting FIPS 140 (FedRAMP requires FIPS-validated).

Artefacts an auditor will ask for
  • Control implementation statement for IA-7 citing the system mission and inheritance from common controls
  • Identity proofing records for high assurance accounts
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
IA-8
Identification and Authentication (Non-Organizational Users)

Uniquely identify and authenticate non-organizational users (e.g., federal customers).

Artefacts an auditor will ask for
  • Control implementation statement for IA-8 citing the system mission and inheritance from common controls
  • Authenticator lifecycle procedure including reset and revocation
  • Identification and authentication policy
  • MFA enrolment report for all privileged and remote users
  • Password policy configuration export from the identity provider
  • Service account credential vault inventory and rotation logs
Where this commonly fails
  • Federation trust relationships not reviewed when partnerships change
  • MFA exceptions granted indefinitely without compensating controls
  • Shared accounts authenticate without traceability to individuals
  • Default vendor credentials remain on appliances and IoT devices

IR Incident Response

IR-1
Policy and Procedures

Requires an incident response policy and supporting procedures to be developed, documented, disseminated, reviewed and updated on a defined cycle.

Artefacts an auditor will ask for
  • Control implementation statement for IR-1 citing the system mission and inheritance from common controls
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Third party incident responder retainer expired
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-2
Incident Response Training

Requires incident response training for system users consistent with their assigned roles, within a defined period of assuming the role and periodically thereafter.

Artefacts an auditor will ask for
  • Control implementation statement for IR-2 citing the system mission and inheritance from common controls
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Third party incident responder retainer expired
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
IR-3
Incident Response Testing

Requires the incident response capability to be tested at a defined frequency using defined tests, to determine its effectiveness, and the results documented.

Artefacts an auditor will ask for
  • Control implementation statement for IR-3 citing the system mission and inheritance from common controls
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
Where this commonly fails
  • Third party incident responder retainer expired
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-4
Incident Handling

Implement IR capability for preparation, detection/analysis, containment, eradication, recovery.

Artefacts an auditor will ask for
  • Control implementation statement for IR-4 citing the system mission and inheritance from common controls
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
Where this commonly fails
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-5
Incident Monitoring

Track and document incidents.

Artefacts an auditor will ask for
  • Control implementation statement for IR-5 citing the system mission and inheritance from common controls
  • Incident response team roster with on call rotation
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
Where this commonly fails
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
  • Notification timelines miss jurisdictional regulatory deadlines
IR-6
Incident Reporting

Require personnel to report incidents to organizational authorities within FedRAMP timeframe; report to FedRAMP PMO and US-CERT.

Artefacts an auditor will ask for
  • Control implementation statement for IR-6 citing the system mission and inheritance from common controls
  • Tabletop and live exercise after action reports
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
Where this commonly fails
  • Detection coverage gaps allow incidents to be discovered externally
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
IR-7
Incident Response Assistance

Provide IR support resource (help desk, support group) for incident handling assistance.

Artefacts an auditor will ask for
  • Control implementation statement for IR-7 citing the system mission and inheritance from common controls
  • Incident ticket samples covering detection, containment, and lessons learned
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
  • Notification timelines miss jurisdictional regulatory deadlines
  • Third party incident responder retainer expired
IR-8
Incident Response Plan

Develop and implement IRP; review and update annually; distribute.

Artefacts an auditor will ask for
  • Control implementation statement for IR-8 citing the system mission and inheritance from common controls
  • Forensic toolkit readiness checklist and chain of custody templates
  • Regulatory notification procedure with jurisdiction specific timelines
  • Incident response plan with severity definitions and escalation paths
  • Incident response team roster with on call rotation
Where this commonly fails
  • Severity criteria inconsistent across teams leading to under reporting
  • Lessons learned captured but corrective actions not tracked to closure
  • Notification timelines miss jurisdictional regulatory deadlines

MA Maintenance

MA-1
Policy and Procedures

Develop and review maintenance policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for MA-1 citing the system mission and inheritance from common controls
  • Maintenance personnel access list with background check status
  • Remote maintenance session logs with MFA and supervision evidence
  • Tool sanitisation records for media leaving the facility
  • Vendor maintenance agreements with security clauses
Where this commonly fails
  • Emergency maintenance performed without retrospective documentation
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
MA-2
Controlled Maintenance

Schedule, document, review records of maintenance, repair, replacement of components.

Artefacts an auditor will ask for
  • Control implementation statement for MA-2 citing the system mission and inheritance from common controls
  • Remote maintenance session logs with MFA and supervision evidence
  • Tool sanitisation records for media leaving the facility
  • Vendor maintenance agreements with security clauses
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
Where this commonly fails
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
  • Maintenance tools not sanitised before removal from secure areas
MA-3
Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]

Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency]

Artefacts an auditor will ask for
  • Control implementation statement for MA-3 citing the system mission and inheritance from common controls
  • Tool sanitisation records for media leaving the facility
  • Vendor maintenance agreements with security clauses
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
Where this commonly fails
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
MA-4
Nonlocal Maintenance

Approve and monitor nonlocal maintenance activities; use strong authentication.

Artefacts an auditor will ask for
  • Control implementation statement for MA-4 citing the system mission and inheritance from common controls
  • Vendor maintenance agreements with security clauses
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
  • Maintenance personnel access list with background check status
  • Remote maintenance session logs with MFA and supervision evidence
Where this commonly fails
  • Maintenance vendors lack signed confidentiality and security clauses
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
  • Maintenance tools not sanitised before removal from secure areas
MA-5
Maintenance Personnel

Establish process for authorizing maintenance personnel; maintain list of authorized personnel; supervise unauthorized.

Artefacts an auditor will ask for
  • Control implementation statement for MA-5 citing the system mission and inheritance from common controls
  • System maintenance policy and approved maintenance windows
  • Maintenance ticket records with approvals and post change verification
  • Maintenance personnel access list with background check status
  • Remote maintenance session logs with MFA and supervision evidence
Where this commonly fails
  • Vendor engineers granted standing access rather than session based access
  • Remote maintenance sessions unmonitored after initial authentication
  • Maintenance tools not sanitised before removal from secure areas
MA-6
Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure

Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure

Artefacts an auditor will ask for
  • Support contracts
Where this commonly fails
  • No SLA

MP Media Protection

MP-1
Policy and Procedures

Develop and review media protection policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for MP-1 citing the system mission and inheritance from common controls
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
Where this commonly fails
  • Backup tapes shipped without tamper evident packaging
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
MP-2
Media Access

Restrict access to FedRAMP-defined types of digital and non-digital media to authorized personnel.

Artefacts an auditor will ask for
  • Control implementation statement for MP-2 citing the system mission and inheritance from common controls
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
Where this commonly fails
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
MP-3
Media Marking

Mark system media indicating distribution limitations, handling caveats, security markings.

Artefacts an auditor will ask for
  • Control implementation statement for MP-3 citing the system mission and inheritance from common controls
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
Where this commonly fails
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
MP-4
Media Storage

Physically control and securely store FedRAMP-defined types of media within FedRAMP-defined controlled areas.

Artefacts an auditor will ask for
  • Control implementation statement for MP-4 citing the system mission and inheritance from common controls
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
Where this commonly fails
  • Media classification labels missing on physical assets
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
MP-5
Media Transport

Protect and control media during transport outside controlled areas; maintain accountability; document activities; restrict transport to authorized personnel.

Artefacts an auditor will ask for
  • Control implementation statement for MP-5 citing the system mission and inheritance from common controls
  • Removable media usage policy and DLP enforcement evidence
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
Where this commonly fails
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
  • Backup tapes shipped without tamper evident packaging
MP-6
Media Sanitization

Sanitize media prior to disposal, release, or reuse using FedRAMP-defined methods (NIST SP 800-88).

Artefacts an auditor will ask for
  • Control implementation statement for MP-6 citing the system mission and inheritance from common controls
  • Media transport chain of custody logs
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
Where this commonly fails
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
MP-7
Media Use

Restrict or prohibit use of FedRAMP-defined types of media on FedRAMP-defined systems using safeguards.

Artefacts an auditor will ask for
  • Control implementation statement for MP-7 citing the system mission and inheritance from common controls
  • Encryption configuration for portable storage devices
  • Media protection policy covering electronic and physical media
  • Media inventory and labelling scheme by data classification
  • Sanitisation and destruction certificates from approved disposal vendor
  • Removable media usage policy and DLP enforcement evidence
Where this commonly fails
  • Decommissioned drives stored unencrypted while awaiting destruction
  • USB usage permitted without DLP inspection or encryption
  • Destruction certificates lack serial numbers tying back to inventory
  • Backup tapes shipped without tamper evident packaging

PE Physical and Environmental Protection

PE-1
Policy and Procedures

Develop and review physical/environmental policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for PE-1 citing the system mission and inheritance from common controls
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Visitor logs incomplete or escort sign offs missing
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-10
Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system

Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system

Artefacts an auditor will ask for
  • Control implementation statement for PE-10 citing the system mission and inheritance from common controls
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-11
Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power

Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power

Artefacts an auditor will ask for
  • Control implementation statement for PE-11 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-12
Emergency Lighting

Employ and maintain automatic emergency lighting activating on power outage covering emergency exits.

Artefacts an auditor will ask for
  • Control implementation statement for PE-12 citing the system mission and inheritance from common controls
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-13
Fire Protection

Employ and maintain fire suppression and detection devices independent of energy source.

Artefacts an auditor will ask for
  • Control implementation statement for PE-13 citing the system mission and inheritance from common controls
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-14
Environmental Controls

Maintain temperature and humidity within FedRAMP-defined acceptable levels; monitor at FedRAMP frequency.

Artefacts an auditor will ask for
  • Control implementation statement for PE-14 citing the system mission and inheritance from common controls
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
  • Visitor logs incomplete or escort sign offs missing
PE-15
Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel

Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel

Artefacts an auditor will ask for
  • Control implementation statement for PE-15 citing the system mission and inheritance from common controls
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-16
Delivery and Removal

Authorize and control system components entering/exiting facility; maintain records.

Artefacts an auditor will ask for
  • Inventory in/out logs
Where this commonly fails
  • No records
PE-17
Alternate Work Site

Determine alternate work sites; employ FedRAMP-defined controls at alternate sites; assess effectiveness.

Artefacts an auditor will ask for
  • Control implementation statement for PE-17 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
  • Visitor logs incomplete or escort sign offs missing
PE-2
Physical Access Authorizations

Develop, approve, maintain list of individuals with authorized facility access; review at least quarterly (FedRAMP).

Artefacts an auditor will ask for
  • Control implementation statement for PE-2 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Visitor logs incomplete or escort sign offs missing
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
PE-3
Physical Access Control

Enforce physical access at entry/exit points; verify authorizations; control ingress/egress; maintain audit logs.

Artefacts an auditor will ask for
  • Control implementation statement for PE-3 citing the system mission and inheritance from common controls
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Visitor logs incomplete or escort sign offs missing
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-4
Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls]

Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls]

Artefacts an auditor will ask for
  • Control implementation statement for PE-4 citing the system mission and inheritance from common controls
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-5
Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output

Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output

Artefacts an auditor will ask for
  • Control implementation statement for PE-5 citing the system mission and inheritance from common controls
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-6
Monitoring Physical Access

Monitor physical access to facility; review access logs at least weekly (FedRAMP); coordinate review with IR.

Artefacts an auditor will ask for
  • Control implementation statement for PE-6 citing the system mission and inheritance from common controls
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
Where this commonly fails
  • Environmental sensor alerts route to unmonitored mailboxes
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
PE-8
Visitor Access Records

Maintain visitor access records for FedRAMP-defined period (1 year); review records monthly (FedRAMP).

Artefacts an auditor will ask for
  • Control implementation statement for PE-8 citing the system mission and inheritance from common controls
  • Environmental monitoring readings for temperature, humidity, and water leak sensors
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
PE-9
Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction

Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction

Artefacts an auditor will ask for
  • Control implementation statement for PE-9 citing the system mission and inheritance from common controls
  • Fire suppression and UPS maintenance records
  • Physical security policy and facility risk assessment
  • Badge access system audit log and door alarm reports
  • Visitor sign in records with escort assignment
  • CCTV retention configuration and footage spot check evidence
Where this commonly fails
  • Server room doors propped open during cooling failures
  • CCTV coverage gaps at loading docks and equipment delivery areas
  • Tailgating observed without challenge during walkthroughs
  • Visitor logs incomplete or escort sign offs missing

PL Planning

PL-1
Policy and Procedures

Develop and review planning policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for PL-1 citing the system mission and inheritance from common controls
  • Concept of operations describing system mission and data flows
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
Where this commonly fails
  • Planning artefacts lack version history and approval signatures
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
PL-10
Baseline Selection. Select a control baseline for the system

Baseline Selection. Select a control baseline for the system

Artefacts an auditor will ask for
  • Control implementation statement for PL-10 citing the system mission and inheritance from common controls
  • Concept of operations describing system mission and data flows
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
Where this commonly fails
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
PL-11
Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions

Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions

Artefacts an auditor will ask for
  • Control implementation statement for PL-11 citing the system mission and inheritance from common controls
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
Where this commonly fails
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
  • Architecture diagrams missing third party and SaaS dependencies
PL-2
System Security and Privacy Plans

Develop SSP that aligns with FedRAMP template; review and update annually.

Artefacts an auditor will ask for
  • Control implementation statement for PL-2 citing the system mission and inheritance from common controls
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
Where this commonly fails
  • Planning artefacts lack version history and approval signatures
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
PL-4
Rules of Behavior

Establish and provide rules describing user responsibilities; receive signed acknowledgement.

Artefacts an auditor will ask for
  • Control implementation statement for PL-4 citing the system mission and inheritance from common controls
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
  • Concept of operations describing system mission and data flows
  • Privacy and security integration documentation
Where this commonly fails
  • Privacy considerations addressed separately from security planning
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
  • Architecture diagrams missing third party and SaaS dependencies
PL-8
Security and Privacy Architectures

Develop, document, maintain security/privacy architectures; review annually.

Artefacts an auditor will ask for
  • Control implementation statement for PL-8 citing the system mission and inheritance from common controls
  • Privacy and security integration documentation
  • System security plan with control allocation matrix
  • Rules of behaviour signed by users including privileged personnel
  • Information security architecture diagrams current within twelve months
  • Security planning meeting minutes with stakeholder attendance
Where this commonly fails
  • System security plan not refreshed after material system changes
  • Rules of behaviour acknowledged once but not refreshed annually
  • Architecture diagrams missing third party and SaaS dependencies
  • Planning artefacts lack version history and approval signatures

PM Program Management

PM-1
Information Security Program Plan

Develop and disseminate an organization-wide information security program plan. Review, update, and protect from unauthorized disclosure.

Artefacts an auditor will ask for
  • Program plan document
  • Approval
  • Distribution list
Where this commonly fails
  • Plan stale or generic
PM-10
Authorization Process

Manage the security and privacy state of systems through assessment and authorization processes.

Artefacts an auditor will ask for
  • ATO letters
  • Continuous authorization records
Where this commonly fails
  • Authorization stale
PM-11
Mission and Business Process Definition

Define mission and business processes with consideration for information security and privacy.

Artefacts an auditor will ask for
  • Process map
  • Privacy and security touchpoints documented
Where this commonly fails
  • Privacy considered only at the end
PM-12
Insider Threat Program

Implement an insider threat program including cross-functional teams and information sharing.

Artefacts an auditor will ask for
  • Insider threat charter
  • Team roster
  • Indicator catalog
  • Case management process
Where this commonly fails
  • No HR/Legal/IT working group
PM-13
Security and Privacy Workforce

Establish a security and privacy workforce development and improvement program.

Artefacts an auditor will ask for
  • Role definitions
  • Skills matrix
  • Training plan
Where this commonly fails
  • No role-based pathway
PM-14
Testing, Training, and Monitoring

Plan, implement and maintain processes for testing, training and monitoring across the program.

Artefacts an auditor will ask for
  • Annual T&T schedule
  • Monitoring program documentation
Where this commonly fails
  • Testing siloed by system
PM-15
Security and Privacy Groups and Associations

Establish and institutionalize contact with selected groups and associations.

Artefacts an auditor will ask for
  • ISAC memberships
  • Conference participation log
Where this commonly fails
  • No threat-sharing memberships
PM-16
Threat Awareness Program

Implement a threat awareness program with cross-organization information-sharing capability.

Artefacts an auditor will ask for
  • Threat bulletins
  • Distribution lists
  • TIP integration
Where this commonly fails
  • TI not actioned
PM-17
Protecting CUI on External Systems

Establish policy and procedures to ensure CUI is protected on external systems.

Artefacts an auditor will ask for
  • CUI policy
  • Contract flow-down language
  • External system assessment evidence
Where this commonly fails
  • No CUI clauses in contracts
PM-18
Privacy Program Plan

Develop and disseminate an organization-wide privacy program plan that includes program objectives, structure, roles, and governance.

Artefacts an auditor will ask for
  • Privacy program plan
  • Governance structure
  • Review cadence
Where this commonly fails
  • No privacy program plan distinct from security
PM-19
Privacy Program Leadership Role

Appoint a senior agency official for privacy with the mission and resources to manage privacy.

Artefacts an auditor will ask for
  • SAOP appointment memo
  • Privacy role description
Where this commonly fails
  • No SAOP
PM-2
Information Security Program Leadership Role

Appoint a senior agency information security officer with mission, resources, authority to manage the program.

Artefacts an auditor will ask for
  • Appointment memo
  • Role description
  • Reporting line documentation
Where this commonly fails
  • Role split between functions
  • No charter
PM-20
Dissemination of Privacy Program Information

Maintain a central resource webpage on the organization's principal public website that serves as a central source of information about the organization's privacy program.

Artefacts an auditor will ask for
  • Privacy webpage URL
  • Content review log
Where this commonly fails
  • Privacy notices out of date
PM-21
Accounting of Disclosures

Develop and maintain an accurate accounting of disclosures of personally identifiable information.

Artefacts an auditor will ask for
  • Disclosure register
  • Request handling SOP
Where this commonly fails
  • No disclosure register
PM-22
Personally Identifiable Information Quality Management

Develop and document policies and procedures for ensuring PII quality.

Artefacts an auditor will ask for
  • PII quality SOP
  • Data correction workflow
Where this commonly fails
  • No correction workflow
PM-23
Data Governance Body

Establish a data governance body consisting of defined roles with defined responsibilities.

Artefacts an auditor will ask for
  • DGB charter
  • Member roster
  • Meeting minutes
Where this commonly fails
  • DGB exists in name only
PM-24
Data Integrity Board

Establish a data integrity board to oversee data sharing and matching agreements.

Artefacts an auditor will ask for
  • DIB charter
  • Approved data sharing agreements
Where this commonly fails
  • No oversight of data matching
PM-25
Minimization of PII Used in Testing, Training, and Research

Develop, document, and implement policies and procedures that address the use of PII for internal testing, training, and research.

Artefacts an auditor will ask for
  • PII minimization policy
  • Anonymization SOP
  • Test environment review
Where this commonly fails
  • Production data copied to test
PM-26
Complaint Management

Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practices.

Artefacts an auditor will ask for
  • Complaint intake form
  • SLA
  • Resolution log
Where this commonly fails
  • No tracked SLA
PM-27
Privacy Reporting

Develop and disseminate privacy reports to oversight bodies and other constituents at defined frequency.

Artefacts an auditor will ask for
  • Privacy report template
  • Distribution log
Where this commonly fails
  • No external privacy reporting
PM-28
Risk Framing

Identify and document assumptions, constraints, priorities and trade-offs that affect risk decisions.

Artefacts an auditor will ask for
  • Risk framing document
  • Trade-off log
Where this commonly fails
  • Framing assumptions undocumented
PM-29
Risk Management Program Leadership Roles

Appoint a senior accountable official for risk management and establish a risk executive function.

Artefacts an auditor will ask for
  • Appointment memo
  • Risk Executive Function charter
Where this commonly fails
  • No risk executive function
PM-3
Information Security and Privacy Resources

Include resources needed to implement the security and privacy programs and document exceptions to funding.

Artefacts an auditor will ask for
  • Annual security budget
  • Exception register
Where this commonly fails
  • Budget not tracked separately
PM-30
Supply Chain Risk Management Strategy

Develop an organization-wide strategy for managing supply chain risks.

Artefacts an auditor will ask for
  • SCRM strategy
  • Tier 1/2 supplier risk assessment process
Where this commonly fails
  • No SCRM strategy
PM-31
Continuous Monitoring Strategy

Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs.

Artefacts an auditor will ask for
  • ConMon strategy
  • Metric catalog
  • Reporting cadence
Where this commonly fails
  • No formal ConMon strategy
PM-32
Purposing

Analyze defined systems or system components, including hardware and software, to determine their intended purpose, and that they perform only that purpose.

Artefacts an auditor will ask for
  • Component purpose register
  • Verification activity records
Where this commonly fails
  • No purposing analysis
PM-4
Plan of Action and Milestones Process

Implement a process to ensure POA&Ms for the security and privacy programs and associated systems are developed and maintained.

Artefacts an auditor will ask for
  • POA&M template
  • Aging report
  • Closure evidence
Where this commonly fails
  • POA&Ms stale
  • No aging metric
PM-5
System Inventory

Develop and update an inventory of organizational systems.

Artefacts an auditor will ask for
  • System register
  • Owner mapping
  • Update cadence
Where this commonly fails
  • Shadow IT not captured
PM-6
Measures of Performance

Develop, monitor, and report on the results of information security and privacy measures of performance.

Artefacts an auditor will ask for
  • KPI/KRI dashboard
  • Reporting cadence
  • Board pack samples
Where this commonly fails
  • Metrics not tied to outcomes
PM-7
Enterprise Architecture

Develop an enterprise architecture integrating security and privacy considerations.

Artefacts an auditor will ask for
  • EA model
  • Security and privacy integration narrative
Where this commonly fails
  • EA not maintained
PM-8
Critical Infrastructure Plan

Address information security and privacy issues in the development of a critical infrastructure and key resources protection plan.

Artefacts an auditor will ask for
  • CI/KR plan with security and privacy sections
Where this commonly fails
  • No CI mapping for the organization
PM-9
Risk Management Strategy

Develop a comprehensive strategy to manage risk including threat, vulnerability, impact, likelihood and risk tolerance.

Artefacts an auditor will ask for
  • Risk management strategy
  • Risk appetite statement
  • Methodology document
Where this commonly fails
  • Appetite not approved at board level

PS Personnel Security

PS-1
Policy and Procedures

Develop and review personnel security policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for PS-1 citing the system mission and inheritance from common controls
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Background checks not re run when employees move to higher risk roles
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
PS-2
Position Risk Designation

Assign risk designation to positions; review and update at least every three years.

Artefacts an auditor will ask for
  • Control implementation statement for PS-2 citing the system mission and inheritance from common controls
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
PS-3
Personnel Screening

Screen individuals prior to authorizing access; rescreen at FedRAMP frequency per position risk; US citizenship may apply.

Artefacts an auditor will ask for
  • Control implementation statement for PS-3 citing the system mission and inheritance from common controls
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
Where this commonly fails
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
PS-4
Personnel Termination

Disable access and revoke authenticators within FedRAMP-defined time (same day); conduct exit interview; retrieve property.

Artefacts an auditor will ask for
  • Control implementation statement for PS-4 citing the system mission and inheritance from common controls
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
Where this commonly fails
  • Termination access removal exceeds documented SLA
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
PS-5
Personnel Transfer

Review/confirm ongoing operational need for access when personnel transfer; modify access; notify within FedRAMP timeframe.

Artefacts an auditor will ask for
  • Control implementation statement for PS-5 citing the system mission and inheritance from common controls
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
Where this commonly fails
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
PS-6
Access Agreements

Develop access agreements; review and update annually; require signature before access.

Artefacts an auditor will ask for
  • Control implementation statement for PS-6 citing the system mission and inheritance from common controls
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
Where this commonly fails
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
PS-7
External Personnel Security

Establish personnel security requirements for external providers; require providers to notify within FedRAMP timeframe of personnel changes.

Artefacts an auditor will ask for
  • Control implementation statement for PS-7 citing the system mission and inheritance from common controls
  • Acknowledgement of access agreements signed at hire
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Sanctions applied informally without HR documentation
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
PS-8
Personnel Sanctions

Employ formal sanctions for personnel failing to comply with security/privacy policies; notify defined personnel within FedRAMP timeframe.

Artefacts an auditor will ask for
  • Control implementation statement for PS-8 citing the system mission and inheritance from common controls
  • Personnel security policy and position risk designation matrix
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
Where this commonly fails
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
PS-9
Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions

Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions

Artefacts an auditor will ask for
  • Control implementation statement for PS-9 citing the system mission and inheritance from common controls
  • Background screening completion records by role tier
  • Termination and transfer access removal evidence within SLA
  • Sanctions policy with documented application history
  • Third party personnel screening attestations
  • Acknowledgement of access agreements signed at hire
Where this commonly fails
  • Contractor screening relies on vendor attestation without sampling
  • Position risk designations not reviewed when responsibilities change
  • Background checks not re run when employees move to higher risk roles
  • Termination access removal exceeds documented SLA

PT PII Processing and Transparency

PT-1
Policy and Procedures

Develop, document, disseminate PII processing and transparency policy and procedures.

Artefacts an auditor will ask for
  • PT policy
  • Procedures
  • Owner memo
  • Review record
Where this commonly fails
  • No privacy-specific policy
PT-2
Authority to Process PII

Determine and document the authority that permits processing of PII; restrict processing to that authority.

Artefacts an auditor will ask for
  • Authority register per processing activity
  • Mapping to lawful basis
Where this commonly fails
  • No authority assessment
  • Vague lawful basis
PT-3
PII Processing Purposes

Identify and document the purposes for processing PII. Describe purposes in notices, restrict processing to identified purposes.

Artefacts an auditor will ask for
  • Purpose register
  • Notice text mapping
  • Audit of processing against purpose
Where this commonly fails
  • Purposes drift after launch
PT-4
Consent

Implement tools or mechanisms for individuals to consent to the processing of their PII prior to its collection that facilitate informed decisions.

Artefacts an auditor will ask for
  • Consent UX
  • Granular preference centre
  • Audit trail of consents
Where this commonly fails
  • Bundled consent
  • No withdrawal mechanism
PT-5
Privacy Notice

Provide notice to individuals about the processing of PII.

Artefacts an auditor will ask for
  • Privacy notice
  • Last reviewed date
  • Distribution channels
Where this commonly fails
  • Notice misaligned with actual processing
PT-6
System of Records Notice

For systems that process information about US citizens or lawful permanent residents that meets Privacy Act criteria, publish SORN.

Artefacts an auditor will ask for
  • Published SORN
  • Review record
Where this commonly fails
  • No SORN for in-scope systems
PT-7
Specific Categories of PII

Apply additional controls to special categories of PII (SSN, biometric, health). HIGH baseline applies in privacy scope.

Artefacts an auditor will ask for
  • Sensitive PII inventory
  • Additional controls register
  • SSN minimization plan
Where this commonly fails
  • SSN used as primary key
  • Health PII commingled
PT-8
Computer Matching Requirements

Comply with Privacy Act computer matching requirements when systems engage in computer matching.

Artefacts an auditor will ask for
  • Matching agreements
  • Notice publication
Where this commonly fails
  • No matching agreements

RA Risk Assessment

RA-1
Policy and Procedures

Develop and review risk assessment policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for RA-1 citing the system mission and inheritance from common controls
  • Risk register with likelihood, impact, and treatment owners
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
Where this commonly fails
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
RA-2
Security Categorization

Categorize system per FIPS 199; document; review and update annually.

Artefacts an auditor will ask for
  • Control implementation statement for RA-2 citing the system mission and inheritance from common controls
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
Where this commonly fails
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
RA-3
Risk Assessment

Conduct risk assessment annually (FedRAMP); document; review and update.

Artefacts an auditor will ask for
  • Control implementation statement for RA-3 citing the system mission and inheritance from common controls
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
  • Risk assessment methodology approved by leadership
  • Risk register with likelihood, impact, and treatment owners
Where this commonly fails
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
RA-5
Vulnerability Monitoring and Scanning

Scan for vulnerabilities monthly (FedRAMP); OS/network weekly, web app monthly, database monthly; remediate within FedRAMP timeframes (HIGH critical 15d, high 30d).

Artefacts an auditor will ask for
  • Control implementation statement for RA-5 citing the system mission and inheritance from common controls
  • Risk acceptance memos signed by accountable executives
  • Risk assessment methodology approved by leadership
  • Risk register with likelihood, impact, and treatment owners
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
Where this commonly fails
  • Risk register entries lack named owner or due date
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
RA-7
Risk Response

Requires the organisation to respond to findings from security and privacy assessments, monitoring and audits, so identified risk is treated rather than only recorded.

Artefacts an auditor will ask for
  • Control implementation statement for RA-7 citing the system mission and inheritance from common controls
  • Risk register with likelihood, impact, and treatment owners
  • Vulnerability scan reports for internal, external, and authenticated scopes
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
Where this commonly fails
  • Penetration tests scope narrow and exclude key applications
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
RA-9
Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or system services] at [Assignment: organization-defined decision points in the system development life cycle]

Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or system services] at [Assignment: organization-defined decision points in the system development life cycle]

Artefacts an auditor will ask for
  • Control implementation statement for RA-9 citing the system mission and inheritance from common controls
  • Penetration test report with retest evidence
  • Threat intelligence feed subscriptions and triage workflow
  • Risk acceptance memos signed by accountable executives
  • Risk assessment methodology approved by leadership
  • Risk register with likelihood, impact, and treatment owners
Where this commonly fails
  • Scan coverage gaps for containerised and ephemeral workloads
  • Threat intelligence consumed but not operationalised into detections
  • High severity vulnerabilities exceed remediation SLA without risk acceptance
  • Risk register entries lack named owner or due date

SA System and Services Acquisition

SA-1
Policy and Procedures

Requires a system and services acquisition policy and supporting procedures to be developed, documented, disseminated, reviewed and updated on a defined cycle.

Artefacts an auditor will ask for
  • Control implementation statement for SA-1 citing the system mission and inheritance from common controls
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
Where this commonly fails
  • Security requirements absent from procurement templates for low value buys
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
SA-10
Developer Configuration Management

Require developer to perform CM during development, implementation, operation; document/track changes; implement only approved changes.

Artefacts an auditor will ask for
  • Control implementation statement for SA-10 citing the system mission and inheritance from common controls
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
Where this commonly fails
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
SA-11
Developer Testing and Evaluation

Require developer to test at FedRAMP-defined depth and coverage; document; correct flaws.

Artefacts an auditor will ask for
  • Control implementation statement for SA-11 citing the system mission and inheritance from common controls
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
SA-15
Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the

Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the

Artefacts an auditor will ask for
  • Control implementation statement for SA-15 citing the system mission and inheritance from common controls
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
Where this commonly fails
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
  • Threat modelling performed inconsistently across product teams
SA-2
Allocation of Resources

Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning; determine, document and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process; and establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.

Artefacts an auditor will ask for
  • Mission and business process planning documentation recording the high-level information security and privacy requirements determined for the system or system service
  • Capital planning and investment control submission or business case showing the resources determined, documented and allocated to protect the system or system service
  • Programming and budgeting documentation showing a discrete line item for information security and privacy
  • Approved budget or spend plan carrying that line item, with its approval record
  • System security and privacy plan section recording the allocated resources and the basis for the amount
  • Records of review of the allocation when requirements or the system change across the system development life cycle
Where this commonly fails
  • Security and privacy requirements determined after the acquisition decision rather than during mission and business process planning
  • Security funding absorbed into a general IT or infrastructure line, so no discrete information security and privacy item exists to evidence
  • Resources named in a plan but never traced through to an approved budget or capital planning submission
  • Privacy resourcing omitted while security resourcing is documented, although the control covers both
  • Line item established once at authorization and not maintained through sustainment and supply chain activity
SA-22
Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support

Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support

Artefacts an auditor will ask for
  • Control implementation statement for SA-22 citing the system mission and inheritance from common controls
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
Where this commonly fails
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
SA-3
System Development Life Cycle

Manage system using SDLC incorporating security/privacy considerations.

Artefacts an auditor will ask for
  • Control implementation statement for SA-3 citing the system mission and inheritance from common controls
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
SA-4
Acquisition Process

Include security/privacy requirements in contracts; FedRAMP-defined assurance requirements.

Artefacts an auditor will ask for
  • Control implementation statement for SA-4 citing the system mission and inheritance from common controls
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
Where this commonly fails
  • Threat modelling performed inconsistently across product teams
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
SA-5
System Documentation

Obtain administrator and user documentation; protect; distribute to FedRAMP-defined personnel.

Artefacts an auditor will ask for
  • Control implementation statement for SA-5 citing the system mission and inheritance from common controls
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
  • Threat modelling and design review evidence for major releases
  • Static and dynamic code analysis reports with finding remediation
Where this commonly fails
  • Open source components used without SBOM or licence review
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
SA-8
Security and Privacy Engineering Principles

Apply FedRAMP-defined systems security and privacy engineering principles in development.

Artefacts an auditor will ask for
  • Control implementation statement for SA-8 citing the system mission and inheritance from common controls
  • Static and dynamic code analysis reports with finding remediation
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
  • Threat modelling performed inconsistently across product teams
SA-9
External System Services

Require providers of external system services to comply with security/privacy requirements; document oversight roles.

Artefacts an auditor will ask for
  • Control implementation statement for SA-9 citing the system mission and inheritance from common controls
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where this commonly fails
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys

SC System and Communications Protection

SC-1
Policy and Procedures

Develop and review system/comms protection policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for SC-1 citing the system mission and inheritance from common controls
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
SC-10
Network Disconnect

Terminate network connection at end of session or after FedRAMP-defined inactivity period (no longer than 30 minutes).

Artefacts an auditor will ask for
  • Control implementation statement for SC-10 citing the system mission and inheritance from common controls
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-12
Cryptographic Key Establishment and Management

Establish and manage cryptographic keys per FedRAMP requirements (FIPS-validated, key escrow/recovery as appropriate).

Artefacts an auditor will ask for
  • Control implementation statement for SC-12 citing the system mission and inheritance from common controls
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-13
Cryptographic Protection

Implement FedRAMP-defined cryptographic uses and approved cryptography (FIPS 140 validated).

Artefacts an auditor will ask for
  • Control implementation statement for SC-13 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
SC-15
Collaborative Computing Devices and Applications

Prohibit remote activation of collaborative computing devices (cameras, mics) without explicit user indication; provide explicit notification.

Artefacts an auditor will ask for
  • Control implementation statement for SC-15 citing the system mission and inheritance from common controls
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
SC-17
Public Key Infrastructure Certificates

Issue public key certificates under FedRAMP-defined policy or obtain from approved service providers.

Artefacts an auditor will ask for
  • Control implementation statement for SC-17 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
SC-18
Mobile Code

Define acceptable and unacceptable mobile code; authorize use; monitor.

Artefacts an auditor will ask for
  • Mobile code policy
Where this commonly fails
  • No policy
SC-2
Separation of System and User Functionality

Separate user functionality from system management functionality.

Artefacts an auditor will ask for
  • Control implementation statement for SC-2 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-20
Secure Name/Address Resolution Service (Authoritative)

Provide artifacts for additional data origin authentication and integrity verification (DNSSEC) for child zones; FedRAMP requires DNSSEC.

Artefacts an auditor will ask for
  • Control implementation statement for SC-20 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-21
Secure Name/Address Resolution Service (Recursive or Caching Resolver)

Request and perform data origin authentication and data integrity verification on name/address resolution responses; DNSSEC validation.

Artefacts an auditor will ask for
  • Control implementation statement for SC-21 citing the system mission and inheritance from common controls
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-22
Architecture and Provisioning for Name/Address Resolution Service

Ensure DNS systems are fault-tolerant and implement role separation.

Artefacts an auditor will ask for
  • Control implementation statement for SC-22 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
SC-23
Session Authenticity

Protect authenticity of communications sessions.

Artefacts an auditor will ask for
  • Control implementation statement for SC-23 citing the system mission and inheritance from common controls
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-28
Protection of Information at Rest

Protect confidentiality and integrity of FedRAMP-defined information at rest.

Artefacts an auditor will ask for
  • Control implementation statement for SC-28 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
SC-39
Process Isolation

Maintain separate execution domain for each executing system process.

Artefacts an auditor will ask for
  • Control implementation statement for SC-39 citing the system mission and inheritance from common controls
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Flat networks expose sensitive workloads without segmentation
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-4
Information in Shared System Resources

Prevent unauthorized and unintended information transfer via shared system resources.

Artefacts an auditor will ask for
  • Control implementation statement for SC-4 citing the system mission and inheritance from common controls
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-5
Denial-of-Service Protection

Protect against or limit effects of DoS attacks using FedRAMP-defined safeguards.

Artefacts an auditor will ask for
  • Control implementation statement for SC-5 citing the system mission and inheritance from common controls
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
Where this commonly fails
  • Cryptographic keys stored alongside the data they protect
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
SC-7
Boundary Protection

Monitor/control communications at external boundary and key internal boundaries; implement subnetworks for publicly accessible components.

Artefacts an auditor will ask for
  • Control implementation statement for SC-7 citing the system mission and inheritance from common controls
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
SC-8
Transmission Confidentiality and Integrity

Protect confidentiality and integrity of transmitted information using cryptographic mechanisms.

Artefacts an auditor will ask for
  • Control implementation statement for SC-8 citing the system mission and inheritance from common controls
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where this commonly fails
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
  • Flat networks expose sensitive workloads without segmentation

SI System and Information Integrity

SI-1
Policy and Procedures

Develop and review system/information integrity policy at least annually.

Artefacts an auditor will ask for
  • Control implementation statement for SI-1 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • Input validation handled inconsistently across microservices
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
SI-10
Information Input Validation

Check validity of FedRAMP-defined information inputs.

Artefacts an auditor will ask for
  • Control implementation statement for SI-10 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-11
Error Handling

Generate error messages providing necessary info without revealing sensitive info; reveal only to authorized.

Artefacts an auditor will ask for
  • Error handling review
Where this commonly fails
  • Stack traces exposed
SI-12
Information Management and Retention

Manage and retain information consistent with applicable laws, regulations, policies, standards.

Artefacts an auditor will ask for
  • Control implementation statement for SI-12 citing the system mission and inheritance from common controls
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
Where this commonly fails
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
SI-16
Memory Protection

Implement FedRAMP-defined safeguards to protect memory from unauthorized code execution (DEP, ASLR).

Artefacts an auditor will ask for
  • Control implementation statement for SI-16 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
  • Input validation handled inconsistently across microservices
SI-2
Flaw Remediation

Identify, report, and correct system flaws; remediate within FedRAMP-defined timeframes (HIGH critical 15d, high 30d).

Artefacts an auditor will ask for
  • Control implementation statement for SI-2 citing the system mission and inheritance from common controls
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
Where this commonly fails
  • Input validation handled inconsistently across microservices
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-3
Malicious Code Protection

Implement signature-based and non-signature-based malicious code protection; configure to scan endpoints and entry/exit points.

Artefacts an auditor will ask for
  • Control implementation statement for SI-3 citing the system mission and inheritance from common controls
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-4
System Monitoring

Monitor system to detect attacks; identify unauthorized use; deploy monitoring devices at boundaries and key internal points.

Artefacts an auditor will ask for
  • Control implementation statement for SI-4 citing the system mission and inheritance from common controls
  • Patch deployment reports across server, endpoint, and network estates
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
SI-5
Security Alerts, Advisories, and Directives

Receive alerts/advisories/directives from FedRAMP-defined external organizations (US-CERT, CISA); generate internal; disseminate.

Artefacts an auditor will ask for
  • Control implementation statement for SI-5 citing the system mission and inheritance from common controls
  • Endpoint detection and response coverage report
  • Vulnerability remediation tickets with verification screenshots
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
Where this commonly fails
  • Alert backlog exceeds analyst capacity leading to triage delays
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
SI-7
Software, Firmware, and Information Integrity

Employ integrity verification tools to detect unauthorized changes to software, firmware, information; HIGH only.

Artefacts an auditor will ask for
  • Control implementation statement for SI-7 citing the system mission and inheritance from common controls
  • Input validation standards and code review checklist
  • Security monitoring alert tuning records
  • Patch management policy with severity based SLAs
  • Patch deployment reports across server, endpoint, and network estates
Where this commonly fails
  • Critical patches deployed beyond the policy SLA without exception
  • EDR coverage gaps on legacy operating systems
  • Anti malware signatures not updated on isolated network segments
SI-8
Spam Protection

Employ spam protection at entry/exit points; update spam protection mechanisms when new releases available.

Artefacts an auditor will ask for
  • Email gateway config
Where this commonly fails
  • No spam protection

SR Supply Chain Risk Management

SR-1
Policy and Procedures (SR-1)

Develop, document, disseminate, and review supply chain risk management policy and procedures at defined frequency.

Artefacts an auditor will ask for
  • Control implementation statement for SR-1 citing the system mission and inheritance from common controls
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Vendor risk tier ratings static despite changes in service scope
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
SR-10
Inspection of Systems or Components (SR-10)

Inspect systems or components at defined frequency or upon indications of tampering to detect compromise.

Artefacts an auditor will ask for
  • Control implementation statement for SR-10 citing the system mission and inheritance from common controls
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-11
Component Authenticity (SR-11)

Implement anti-counterfeit policy and procedures to detect and prevent counterfeit components.

Artefacts an auditor will ask for
  • Control implementation statement for SR-11 citing the system mission and inheritance from common controls
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
SR-12
Component Disposal (SR-12)

Dispose of data, documentation, tools, or system components using defined techniques and methods.

Artefacts an auditor will ask for
  • Control implementation statement for SR-12 citing the system mission and inheritance from common controls
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
Where this commonly fails
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
  • Vendor risk tier ratings static despite changes in service scope
SR-2
Supply Chain Risk Management Plan (SR-2)

Develop a C-SCRM plan for managing supply chain risks for systems, components, and services; review and update at defined frequency.

Artefacts an auditor will ask for
  • Control implementation statement for SR-2 citing the system mission and inheritance from common controls
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Vendor risk tier ratings static despite changes in service scope
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
SR-3
Supply Chain Controls and Processes (SR-3)

Establish processes to identify, protect, detect, respond, and recover across the supply chain lifecycle.

Artefacts an auditor will ask for
  • Control implementation statement for SR-3 citing the system mission and inheritance from common controls
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-5
Acquisition Strategies, Tools, and Methods (SR-5)

Employ acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks.

Artefacts an auditor will ask for
  • Control implementation statement for SR-5 citing the system mission and inheritance from common controls
  • Supplier incident notification clauses and exercise records
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
Where this commonly fails
  • Counterfeit detection procedures absent for hardware refresh cycles
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-6
Supplier Assessments and Reviews (SR-6)

Assess and review the supply chain risk posture of suppliers at defined frequency and after significant events.

Artefacts an auditor will ask for
  • Control implementation statement for SR-6 citing the system mission and inheritance from common controls
  • Supply chain risk management policy and program charter
  • Tiered vendor inventory with criticality scoring
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
Where this commonly fails
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
SR-8
Notification Agreements (SR-8)

Establish agreements with suppliers for notification of supply chain compromises and relevant changes.

Artefacts an auditor will ask for
  • Control implementation statement for SR-8 citing the system mission and inheritance from common controls
  • Component authenticity verification evidence for hardware purchases
  • Continuous monitoring scorecards for critical suppliers
  • Contractual flow down of security requirements to subcontractors
  • Supplier incident notification clauses and exercise records
Where this commonly fails
  • Supplier incidents discovered through news rather than contractual notification
  • Flow down clauses present in master agreements but missing from statements of work
  • Sub tier suppliers not identified for critical components
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-53 Rev 5 MODERATE framework page.