zenibit

FedRAMP reference

FedRAMP Key Security Indicators

Every KSI, its NIST control mapping, and whether a machine can verify it continuously or it needs an uploaded artifact.

Key Security Indicators are FedRAMP 20x's replacement for reciting control implementations in prose. Each one states an outcome, maps to the NIST 800-53 controls it subsumes, and is meant to be demonstrated with evidence rather than described. That is what makes them automatable. The green tag marks indicators Zenibit has an automated check implemented for; the rest are satisfied by evidence you provide.

Cybersecurity Education · CED

1 requirements, 0 verifiable by automated check.

KSI-CED-RAT

Reviewing All Training

The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.

Evidence requiredCP-3IR-2PS-6AT-2AT-2.2AT-2.3AT-3.5AT-4IR-2.3AT-3SR-11.1

Change Management · CMT

4 requirements, 0 verifiable by automated check.

KSI-CMT-LMC

Logging Changes

Modifications to the cloud service offering are logged and monitored.

Evidence requiredAU-2CM-3CM-3.2CM-4.2CM-6CM-8.3MA-2

KSI-CMT-RMV

Redeploying vs Modifying

Changes to machine-based information resources are executed through the redeployment of version controlled resources rather than direct modification wherever reasonable.

Evidence requiredCM-2CM-3CM-5CM-6CM-7CM-8.1SI-3

KSI-CMT-RVP

Reviewing Change Procedures

The effectiveness of documented change management procedures is persistently reviewed.

Evidence requiredCM-3CM-3.2CM-3.4CM-5CM-7.1CM-9

KSI-CMT-VTD

Validating Throughout Deployment

Persistent testing and validation of changes throughout deployment is automated.

Evidence requiredCM-3CM-3.2CM-4.2SI-2

Cloud Native Architecture · CNA

8 requirements, 0 verifiable by automated check.

KSI-CNA-DFP

Defining Functionality and Privileges

The functionality and privileges for infrastructure and services are strictly defined.

Evidence requiredCM-2SI-3

KSI-CNA-EIS

Enforcing Intended State

Class B

Optional: Automated services are used to persistently assess the security of all machine-based information resources and automatically enforce their intended operational state.

Class C

Automated services are used to persistently assess the security of all machine-based information resources and automatically enforce their intended operational state.

Evidence requiredCA-2.1CA-7.1

KSI-CNA-IBP

Implementing Best Practices

The use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance.

Evidence requiredAC-17.3CM-2PL-10

KSI-CNA-MAT

Minimizing Attack Surface

Machine-based information resources are persistently reviewed to ensure they have a minimal attack surface and that lateral movement is minimized if compromised.

Evidence requiredAC-17.3AC-18.1AC-18.3AC-20.1CA-9SC-7.3SC-7.4SC-7.5SC-7.8SC-8SC-10SI-10SI-11SI-16

KSI-CNA-OFA

Optimizing for Availability

Machine-based information resources are persistently reviewed to ensure they are appropriately optimized for high availability and rapid recovery.

Evidence required

KSI-CNA-RNT

Restricting Network Traffic

Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.

Evidence requiredAC-17.3CA-9CM-7.1SC-7.5SI-8

KSI-CNA-RVP

Reviewing Protections

The effectiveness of protection against denial of service attacks and other unwanted activity for machine-based information resources is persistently reviewed.

Evidence requiredSC-5SI-8SI-8.2

KSI-CNA-ULN

Using Logical Networking

Logical networking and related capabilities are used and persistently reviewed to enforce traffic flow controls.

Evidence requiredAC-12AC-17.3CA-9SC-4SC-7SC-7.7SC-8SC-10

Identity and Access Management · IAM

6 requirements, 1 verifiable by automated check.

KSI-IAM-AAM

Automating Account Management

The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.

Evidence requiredAC-2.2AC-2.3AC-2.13AC-6.7IA-4.4IA-12IA-12.2IA-12.3IA-12.5

KSI-IAM-APM

Adopting Passwordless Methods

Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.

Automated checkAC-3IA-5.1IA-5.2IA-5.6IA-6AC-2IA-2IA-2.1IA-2.2IA-2.8IA-5IA-8SC-23

KSI-IAM-ELP

Ensuring Least Privilege

Identity and access management measures are used and persistently reviewed to ensure each user or device can only access the resources they need.

Evidence requiredAC-2.5AC-2.6AC-3AC-4AC-6AC-12AC-14AC-17AC-17.1AC-17.2AC-17.3AC-20AC-20.1CM-2.7CM-9IA-2IA-3IA-4IA-4.4IA-5.2IA-5.6IA-11PS-2PS-3PS-4PS-5PS-6SC-4SC-20SC-21SC-22SC-23SC-39SI-3

KSI-IAM-JIT

Authorizing Just-in-Time

A least-privileged, role and attribute-based, and just-in-time security authorization model is used and persistently reviewed for all user and non-user accounts and services.

Evidence requiredAC-2AC-2.1AC-2.2AC-2.3AC-2.4AC-2.6AC-3AC-4AC-5AC-6AC-6.1AC-6.2AC-6.5AC-6.7AC-6.9AC-6.10AC-7AC-20.1AC-17AU-9.4CM-5CM-7CM-7.2CM-7.5CM-9IA-4IA-4.4IA-7PS-2PS-3PS-4PS-5PS-6PS-9RA-5.5SC-2SC-23SC-39

KSI-IAM-SNU

Securing Non-User Authentication

Appropriately secure authentication methods are used and persistently reviewed for non-user accounts and services.

Evidence requiredAC-2AC-2.2AC-4AC-6.5IA-3IA-5.2RA-5.5

KSI-IAM-SUS

Responding to Suspicious Activity

Accounts with privileged access are disabled or otherwise secured in response to suspicious activity.

Evidence requiredAC-2AC-2.1AC-2.3AC-2.13AC-7PS-4PS-8

Incident Response · INR

3 requirements, 0 verifiable by automated check.

KSI-INR-AAR

Generating After Action Reports

Incident after action reports are generated and lessons learned are persistently incorporated.

Evidence requiredIR-3IR-4IR-4.1IR-8

KSI-INR-RIR

Reviewing Incident Response Procedures

The effectiveness of documented incident response procedures is persistently reviewed.

Evidence requiredIR-4IR-4.1IR-6IR-6.1IR-6.3IR-7IR-7.1IR-8IR-8.1SI-4.5

KSI-INR-RPI

Reviewing Past Incidents

Past incidents are persistently reviewed for patterns or vulnerabilities that were not previously apparent or identified.

Evidence requiredIR-3IR-4IR-4.1IR-5IR-8

Monitoring, Logging, and Auditing · MLA

5 requirements, 1 verifiable by automated check.

KSI-MLA-ALA

Authorizing Log Access

Class B

Optional: A least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity.

Class C

A least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity.

Evidence requiredSI-11

KSI-MLA-EVC

Evaluating Configurations

The configuration of machine-based information resources, especially infrastructure as code, is persistently evaluated and tested.

Evidence requiredCA-7CM-2CM-6SI-7.7

KSI-MLA-LET

Logging Event Types

A list of information resources and event types that will be logged, monitored, and audited is maintained and persistently reviewed to ensure these activities occur.

Evidence requiredAC-2.4AC-6.9AC-17.1AC-20.1AU-2AU-7.1AU-12SI-4.4SI-4.5SI-7.7

KSI-MLA-OSM

Operating SIEM Capability

A Security Information and Event Management (SIEM) or similar system(s) is used and persistently reviewed for centralized, tamper-resistant logging of events, activities, and changes.

Automated checkAC-17.1AC-20.1AU-2AU-3AU-3.1AU-4AU-5AU-6.1AU-6.3AU-7AU-7.1AU-8AU-9AU-11IR-4.1SI-4.2SI-4.4SI-7.7

KSI-MLA-RVL

Reviewing Logs

Logs are persistently reviewed and audited.

Evidence requiredAC-2.4AC-6.9AU-2AU-6AU-6.1SI-4SI-4.4

Policy and Inventory · PIY

5 requirements, 0 verifiable by automated check.

KSI-PIY-GIV

Generating Inventories

Authoritative sources are used to automatically generate real-time inventories of all information resources when needed.

Evidence requiredCM-2.2CM-7.5CM-8CM-8.1CM-12CM-12.1CP-2.8

KSI-PIY-RES

Reviewing Executive Support

Executive support for achieving the provider's security goals is persistently reviewed and demonstrated.

Evidence required

KSI-PIY-RIS

Reviewing Investments in Security

The effectiveness of the provider's investments in achieving security goals is persistently reviewed.

Evidence requiredAC-5CA-2CP-2.1CP-4.1IR-3.2PM-3SA-2SA-3SR-2.1

KSI-PIY-RSD

Reviewing Security in the SDLC

The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.

Evidence requiredAC-5AU-3.3CM-3.4PL-8PM-7SA-3SA-8SC-4SC-18SI-10SI-11SI-16

KSI-PIY-RVD

Reviewing Vulnerability Disclosures

The effectiveness of the provider's vulnerability disclosure program is persistently reviewed.

Evidence requiredRA-5.11

Recovery Planning · RPL

4 requirements, 0 verifiable by automated check.

KSI-RPL-ABO

Aligning Backups with Objectives

The alignment of machine-based information resource backups with defined recovery objectives is persistently reviewed.

Evidence requiredCM-2.3CP-6CP-9CP-10CP-10.2SI-12

KSI-RPL-ARP

Aligning Recovery Plan

The alignment of recovery plans with defined recovery objectives is persistently reviewed.

Evidence requiredCP-2CP-2.1CP-2.3CP-4.1CP-6CP-6.1CP-6.3CP-7CP-7.1CP-7.2CP-7.3CP-8CP-8.1CP-8.2CP-10CP-10.2

KSI-RPL-RRO

Reviewing Recovery Objectives

The desired Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and persistently reviewed for alignment with the provider's business needs and capabilities.

Evidence requiredCP-2.3CP-10

KSI-RPL-TRC

Testing Recovery Capabilities

The capability to recover from incidents and contingencies aligned with defined recovery objectives is persistently tested.

Evidence requiredCP-2.1CP-2.3CP-4CP-4.1CP-6CP-6.1CP-9.1CP-10IR-3IR-3.2

Supply Chain Risk · SCR

2 requirements, 0 verifiable by automated check.

KSI-SCR-MIT

Mitigating Supply Chain Risk

Persistently identify, review, and mitigate potential supply chain risks.

Evidence requiredAC-20RA-3.1SA-9SA-10SA-11SA-15.3SA-22SI-7.1SR-5SR-6CA-7.4SC-18

KSI-SCR-MON

Monitoring Supply Chain Risk

Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.

Evidence requiredAC-20CA-3IR-6.3PS-7RA-5SA-9SI-5SR-5SR-6SR-8

Service Configuration · SVC

8 requirements, 1 verifiable by automated check.

KSI-SVC-ACM

Automating Configuration Management

The configuration of machine-based information resources is managed using automation and persistently reviewed for drift.

Evidence requiredAC-2.4CM-2CM-2.2CM-2.3CM-6CM-7.1PL-9PL-10SA-5SI-5SR-10

KSI-SVC-ASM

Automating Secret Management

Management, protection, and regular rotation of digital keys, certificates, and other secrets is automated and persistently reviewed.

Evidence requiredAC-17.2IA-5.2IA-5.6SC-12SC-17

KSI-SVC-EIS

Evaluating and Improving Security

Information resources are persistently evaluated for opportunities to improve security and those improvements are persistently made.

Evidence requiredCM-7.1CM-12.1MA-2PL-8SC-7SC-39SI-2.2SI-4SR-10

KSI-SVC-PRR

Preventing Residual Risk

Class B

Optional: Plans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data.

Class C

Plans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data.

Evidence requiredSC-4

KSI-SVC-RUD

Removing Unwanted Data

Class B

Optional: Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage.

Class C

Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage.

Evidence requiredSI-12.3SI-18.4

KSI-SVC-SIN

Securing Information

Information is encrypted or otherwise secured from unwanted access or modification.

Automated checkAC-1AC-17.2CP-9.8SC-8SC-8.1SC-13SC-20SC-21SC-22SC-23SC-28SC-28.1

KSI-SVC-VCM

Validating Communications

Class B

Optional: The authenticity and integrity of communications between machine-based information resources is persistently validated using automation.

Class C

The authenticity and integrity of communications between machine-based information resources is persistently validated using automation.

Evidence requiredSC-23SI-7.1

KSI-SVC-VRI

Validating Resource Integrity

Use cryptographic methods to validate the integrity of machine-based information resources.

Evidence requiredCM-2.2CM-8.3SC-13SC-23SI-7SI-7.1SR-10

Stop assembling this by hand.

Zenibit tracks these requirements against your live infrastructure and publishes a trust center agencies can verify themselves. Get in touch.