United States

FedRAMP High

410 controls. 299 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

410 controls 299 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

FedRAMP High Evidence & Implementation Kit

410 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

Showing 400 of 410. The kit carries all of them.

CodeControlAlso in
AC-1Policy and Procedures20
AC-10Concurrent Session Control0
AC-11Device Lock12
AC-11(1)Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image8
AC-12Session Termination10
AC-14Permitted Actions Without Identification or Authentication3
AC-17Remote Access20
AC-17(1)Monitoring and Control13
AC-17(2)Protection of Confidentiality and Integrity Using Encryption16
AC-17(3)Managed Access Control Points16
AC-17(4)Privileged Commands and Access12
AC-18Wireless Access9
AC-18(1)Authentication and Encryption10
AC-18(3)Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployme7
AC-18(4)Restrict Configurations by Users0
AC-18(5)Antennas and Transmission Power Levels0
AC-19Access Control for Mobile Devices16
AC-19(5)Full Device or Container-Based Encryption14
AC-2Account Management95
AC-2(1)Automated System Account Management9
AC-2(11)Usage Conditions0
AC-2(12)Account Monitoring for Atypical Usage15
AC-2(13)Disable Accounts for High-Risk Individuals13
AC-2(2)Automated Temporary and Emergency Account Management10
AC-2(3)Disable Accounts19
AC-2(4)Automated Audit Actions12
AC-2(5)Inactivity Logout12
AC-2(7)Privileged User Accounts16
AC-2(9)Restrictions on Use of Shared and Group Accounts15
AC-20Use of External Systems17
AC-20(1)Limits on Authorized Use14
AC-20(2)Portable Storage Devices Restricted Use13
AC-21Information Sharing14
AC-22Publicly Accessible Content11
AC-3Access Enforcement36
AC-4Information Flow Enforcement22
AC-4(21)Physical or Logical Separation of Information Flows15
AC-4(4)Flow Control of Encrypted Information0
AC-5Separation of Duties19
AC-6Least Privilege26
AC-6(1)Authorize Access to Security Functions14
AC-6(10)Prohibit Non-Privileged Users from Executing Privileged Functions15
AC-6(2)Non-Privileged Access for Nonsecurity Functions15
AC-6(3)Network Access to Privileged Commands0
AC-6(5)Privileged Accounts16
AC-6(7)Review of User Privileges20
AC-6(8)Privilege Levels for Code Execution0
AC-6(9)Log Use of Privileged Functions14
AC-7Unsuccessful Logon Attempts14
AC-8System Use Notification5
AT-1Policy and Procedures17
AT-2Literacy Training and Awareness31
AT-2(2)Insider Threat13
AT-2(3)Social Engineering and Mining13
AT-3Role-Based Training29
AT-4Training Records19
AU-1Policy and Procedures15
AU-10Non-Repudiation0
AU-11Audit Record Retention16
AU-12Audit Record Generation23
AU-12(1)System-wide and Time-correlated Audit Trail0
AU-12(3)Changes by Authorized Individuals0
AU-2Event Logging23
AU-3Content of Audit Records19
AU-3(1)Additional Audit Information12
AU-4Audit Log Storage Capacity12
AU-5Response to Audit Logging Process Failures11
AU-5(1)Storage Capacity Warning0
AU-5(2)Real-Time Alerts0
AU-6Audit Record Review, Analysis, and Reporting27
AU-6(1)Automated Process Integration18
AU-6(3)Correlate Audit Record Repositories18
AU-6(4)Central Review and Analysis0
AU-6(5)Integrated Analysis of Audit Records0
AU-6(6)Correlation with Physical Monitoring0
AU-6(7)Permitted Actions0
AU-7Audit Record Reduction and Report Generation12
AU-7(1)Automatic Processing12
AU-8Time Stamps12
AU-9Protection of Audit Information18
AU-9(2)Store on Separate Physical Systems or Components0
AU-9(3)Cryptographic Protection0
AU-9(4)Access by Subset of Privileged Users13
CA-1Policy and Procedures18
CA-2Control Assessments33
CA-2(1)Independent Assessors23
CA-2(2)Specialized Assessments0
CA-2(3)Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organizati11
CA-3Information Exchange18
CA-3(6)Information Exchange | Transfer Authorizations0
CA-5Plan of Action and Milestones30
CA-6Authorization19
CA-7Continuous Monitoring33
CA-7(1)Independent Assessment13
CA-7(4)Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring;17
CA-8Penetration Testing65
CA-8(1)Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system 14
CA-8(2)Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applic12
CA-9Internal System Connections163
CM-1Policy and Procedures13
CM-10Software Usage Restrictions17
CM-11User-Installed Software22
CM-12Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is process20
CM-12(1)Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assig11
CM-14Signed Components0
CM-2Baseline Configuration19
CM-2(2)Automation Support for Accuracy and Currency12
CM-2(3)Retention of Previous Configurations11
CM-2(7)Configure Systems and Components for High-Risk Areas5
CM-3Configuration Change Control18
CM-3(1)Automated Documentation, Notification, and Prohibition0
CM-3(2)Testing, Validation, and Documentation of Changes14
CM-3(4)Security and Privacy Representatives9
CM-3(6)Cryptography Management1
CM-4Impact Analyses17
CM-4(1)Separate Test Environments0
CM-4(2)Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outc14
CM-5Access Restrictions for Change19
CM-5(1)Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and 14
CM-5(5)Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a product15
CM-6Configuration Settings23
CM-6(1)Automated Management, Application, and Verification16
CM-6(2)Respond to Unauthorized Changes0
CM-7Least Functionality20
CM-7(1)Periodic Review17
CM-7(2)Prevent Program Execution16
CM-7(5)Authorized Software Allow-by-Exception18
CM-8System Component Inventory26
CM-8(1)Updates During Installation and Removal13
CM-8(2)Automated Maintenance0
CM-8(3)Automated Unauthorized Component Detection14
CM-8(4)Accountability Information1
CM-9Configuration Management Plan14
CP-1Policy and Procedures17
CP-10System Recovery and Reconstitution21
CP-10(2)System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based7
CP-10(4)Restore Within Time Period0
CP-2Contingency Plan24
CP-2(1)Coordinate with Related Plans10
CP-2(2)Capacity Planning0
CP-2(3)Resume Mission and Business Functions13
CP-2(5)Continue Mission and Business Functions0
CP-2(8)Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions15
CP-3Contingency Training15
CP-3(1)Simulated Events0
CP-4Contingency Plan Testing24
CP-4(1)Coordinate with Related Plans12
CP-4(2)Alternate Processing Site0
CP-6Alternate Storage Site18
CP-6(1)Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to t9
CP-6(2)Recovery Time and Recovery Point Objectives0
CP-6(3)Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline expl5
CP-7Alternate Processing Site15
CP-7(1)Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibi6
CP-7(2)Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines 7
CP-7(3)Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requiremen6
CP-7(4)Preparation for Use0
CP-8Telecommunications Services10
CP-8(1)Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in6
CP-8(2)Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary tele9
CP-8(3)Separation of Primary and Alternate Providers0
CP-8(4)Provider Contingency Plan0
CP-9System Backup23
CP-9(1)Testing for Reliability and Integrity19
CP-9(2)Test Restoration Using Sampling0
CP-9(3)Separate Storage for Critical Information0
CP-9(5)Transfer to Alternate Storage Site0
CP-9(8)System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup informa16
IA-1Policy and Procedures13
IA-11Re-Authentication11
IA-12Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable10
IA-12(2)Identity Proofing | Identity Evidence. Require evidence of individual identification be presented to the registration authority6
IA-12(3)Identity Proofing | Identity Evidence Validation and Verification. Require that the presented identity evidence be validated and verified through [Assignment: organizational define6
IA-12(4)In-Person Validation and Verification0
IA-12(5)Identity Proofing | Address Confirmation. Require that a [Selection: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address 3
IA-2Identification and Authentication (Organizational Users)24
IA-2(1)MFA to Privileged Accounts21
IA-2(12)Acceptance of PIV Credentials5
IA-2(2)MFA to Non-Privileged Accounts19
IA-2(5)Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users t10
IA-2(6)Identification and Authentication (organizational Users) | Access to Accounts , separate Device. Implement multi-factor authentication for [Selection (one or more): local; network;11
IA-2(8)Access to Accounts Replay Resistant12
IA-3Device Identification and Authentication16
IA-4Identifier Management22
IA-4(4)Identifier Management | Identify User Status. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying 9
IA-5Authenticator Management23
IA-5(1)Password-Based Authentication19
IA-5(13)Authenticator Management | Expiration of Cached Authenticators0
IA-5(2)Public Key-Based Authentication11
IA-5(6)Protection of Authenticators19
IA-5(7)Authenticator Management | No Embedded Unencrypted Static Authenticators. Ensure that unencrypted static authenticators are not embedded in applications or other forms of static st13
IA-5(8)Multiple System Accounts0
IA-6Authentication Feedback8
IA-7Cryptographic Module Authentication10
IA-8Identification and Authentication (Non-Organizational Users)19
IA-8(1)Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies. Accept and electronically verify Personal Identity Verification-co5
IA-8(2)Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators. (a) Accept only external authenticators that are NIST-compliant; and (b) Docum5
IA-8(4)Identification and Authentication (non-organizational Users) | Use of Defined Profiles. Conform to the following profiles for identity management [Assignment: organization-defined 4
IR-1Policy and Procedures19
IR-2Incident Response Training39
IR-2(1)Simulated Events0
IR-2(2)Automated Training Environments0
IR-3Incident Response Testing23
IR-3(2)Incident Response Testing | Coordination with Related Plans. Coordinate incident response testing with organizational elements responsible for related plans12
IR-4Incident Handling68
IR-4(1)Automated Incident Handling Processes14
IR-4(11)Incident Handling | Integrated Incident Response Team0
IR-4(2)Incident Handling | Dynamic Reconfiguration0
IR-4(4)Information Correlation0
IR-4(6)Insider Threats0
IR-5Incident Monitoring27
IR-5(1)Automated Tracking, Data Collection, and Analysis0
IR-6Incident Reporting31
IR-6(1)Automated Reporting13
IR-6(3)Incident Reporting | Supply Chain Coordination. Provide incident information to the provider of the product or service and other organizations involved in the supply chain or suppl11
IR-7Incident Response Assistance16
IR-7(1)Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignm10
IR-8Incident Response Plan29
IR-9Information Spillage Response. Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to informatio11
IR-9(2)Information Spillage Response | Training. Provide information spillage response training [Assignment: organization-defined frequency]6
IR-9(3)Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to car4
IR-9(4)Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [A5
MA-1Policy and Procedures8
MA-2Controlled Maintenance14
MA-2(2)Automated Maintenance Activities0
MA-3Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-define9
MA-3(1)Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications8
MA-3(2)Maintenance Tools | Inspect Media. Check media containing diagnostic and test programs for malicious code before the media are used in the system10
MA-3(3)Maintenance Tools | Prevent Unauthorized Removal. Prevent the removal of maintenance equipment containing organizational information by: (a) Verifying that there is no organization12
MA-4Nonlocal Maintenance15
MA-4(3)Comparable Security and Sanitization0
MA-5Maintenance Personnel12
MA-5(1)Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clea6
MA-6Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of 7
MP-1Policy and Procedures14
MP-2Media Access13
MP-3Media Marking13
MP-4Media Storage17
MP-5Media Transport16
MP-6Media Sanitization25
MP-6(1)Review, Approve, Track, Document, Verify0
MP-6(2)Equipment Testing0
MP-6(3)Nondestructive Techniques0
MP-7Media Use13
PE-1Policy and Procedures14
PE-10Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place em6
PE-11Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate 8
PE-11(1)Alternate Power Supply Minimal Operational Capability0
PE-12Emergency Lighting5
PE-13Fire Protection10
PE-13(1)Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined p7
PE-13(2)Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-d6
PE-14Environmental Controls8
PE-14(2)Environmental Controls | Monitoring with Alarms and Notifications0
PE-15Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and know7
PE-15(1)Automation Support0
PE-16Delivery and Removal13
PE-17Alternate Work Site15
PE-18Location of System Components0
PE-2Physical Access Authorizations15
PE-3Physical Access Control19
PE-3(1)System Access0
PE-4Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [As9
PE-5Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the o10
PE-6Monitoring Physical Access16
PE-6(1)Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment. Monitor physical access to the facility where the system resides using physical intrusion alarms and surve10
PE-6(4)Monitoring Physical Access to Systems0
PE-8Visitor Access Records12
PE-8(1)Automated Records Maintenance and Review0
PE-9Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction8
PL-1Policy and Procedures18
PL-10Baseline Selection. Select a control baseline for the system13
PL-11Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions9
PL-2System Security and Privacy Plans28
PL-4Rules of Behavior19
PL-4(1)Rules of Behavior | Social Media and External Site/application Usage Restrictions. Include in the rules of behavior, restrictions on: (a) Use of social media, social networking sit8
PL-8Security and Privacy Architectures16
PS-1Policy and Procedures14
PS-2Position Risk Designation10
PS-3Personnel Screening20
PS-3(3)Personnel Screening | Information Requiring Special Protective Measures. Verify that individuals accessing a system processing, storing, or transmitting information requiring speci9
PS-4Personnel Termination20
PS-4(2)Automated Actions0
PS-5Personnel Transfer18
PS-6Access Agreements15
PS-7External Personnel Security19
PS-8Personnel Sanctions12
PS-9Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions22
RA-1Policy and Procedures86
RA-2Security Categorization28
RA-3Risk Assessment33
RA-3(1)Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; an17
RA-5Vulnerability Monitoring and Scanning28
RA-5(11)Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and syste8
RA-5(2)Update Vulnerabilities to be Scanned15
RA-5(3)Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage14
RA-5(4)Discoverable Information0
RA-5(5)Privileged Access10
RA-5(8)Vulnerability Monitoring and Scanning | Review Historic Audit Logs0
RA-7Risk Response11
RA-9Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or sy18
SA-1Policy and Procedures18
SA-10Developer Configuration Management13
SA-11Developer Testing and Evaluation19
SA-11(1)Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify c13
SA-11(2)Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling a12
SA-15Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitl16
SA-15(3)Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At6
SA-16Developer-Provided Training0
SA-17Developer Security and Privacy Architecture and Design0
SA-2Allocation of Resources11
SA-21Developer Screening0
SA-22Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the fo18
SA-3System Development Life Cycle21
SA-4Acquisition Process22
SA-4(1)Acquisition Process | Functional Properties of Controls. Require the developer of the system, system component, or system service to provide a description of the functional propert5
SA-4(10)Use of Approved PIV Products3
SA-4(2)Acquisition Process | Design and Implementation Information for Controls. Require the developer of the system, system component, or system service to provide design and implementat5
SA-4(5)System, Component, and Service Configurations0
SA-4(9)Acquisition Process | Functions, Ports, Protocols, and Services in Use. Require the developer of the system, system component, or system service to identify the functions, ports, p7
SA-5System Documentation13
SA-8Security and Privacy Engineering Principles19
SA-9External System Services30
SA-9(1)External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information se17
SA-9(2)Identification of Functions, Ports, Protocols, and Services9
SA-9(5)External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system service16
SC-1Policy and Procedures13
SC-10Network Disconnect10
SC-12Cryptographic Key Establishment and Management15
SC-12(1)Availability0
SC-13Cryptographic Protection22
SC-15Collaborative Computing Devices and Applications5
SC-17Public Key Infrastructure Certificates9
SC-18Mobile Code12
SC-2Separation of System and User Functionality13
SC-20Secure Name/Address Resolution Service (Authoritative)5
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)6
SC-22Architecture and Provisioning for Name/Address Resolution Service5
SC-23Session Authenticity17
SC-24Fail in Known State0
SC-28Protection of Information at Rest23
SC-28(1)Cryptographic Protection16
SC-3Security Function Isolation0
SC-39Process Isolation9
SC-4Information in Shared System Resources11
SC-45System Time Synchronization. Synchronize system clocks within and between systems and system components13
SC-45(1)System Time Synchronization | Synchronization with Authoritative Time Source. (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: 9
SC-5Denial-of-Service Protection15
SC-7Boundary Protection25
SC-7(10)Prevent Exfiltration0
SC-7(12)Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system comp13
SC-7(18)Boundary Protection | Fail Secure. Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device4
SC-7(20)Dynamic Isolation and Segregation0
SC-7(21)Isolation of System Components0
SC-7(3)Access Points17
SC-7(4)External Telecommunications Services13
SC-7(5)Deny by Default Allow by Exception17
SC-7(7)Split Tunneling for Remote Devices8
SC-7(8)Route Traffic to Authenticated Proxy Servers17
SC-8Transmission Confidentiality and Integrity26
SC-8(1)Cryptographic Protection20
SI-1Policy and Procedures14
SI-10Information Input Validation13
SI-11Error Handling6
SI-12Information Management and Retention26
SI-16Memory Protection8
SI-2Flaw Remediation26
SI-2(2)Automated Flaw Remediation Status14
SI-2(3)Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the follo15
SI-3Malicious Code Protection25
SI-4System Monitoring24
SI-4(1)System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system13
SI-4(10)Visibility of Encrypted Communications0
SI-4(11)Analyze Communications Traffic Anomalies0
SI-4(12)Automated Organization-Generated Alerts0
SI-4(14)Wireless Intrusion Detection0
SI-4(16)System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system12
SI-4(18)System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to de16
SI-4(19)Risk for Individuals0
SI-4(2)Automated Tools and Mechanisms for Real-Time Analysis14
SI-4(20)Privileged Users0
SI-4(22)Unauthorized Network Services0
SI-4(23)System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-13
SI-4(4)Inbound and Outbound Communications Traffic14
SI-4(5)System-Generated Alerts14
SI-5Security Alerts, Advisories, and Directives23
SI-5(1)Automated Alerts and Advisories0
SI-6Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the10
SI-7Software, Firmware, and Information Integrity18
SI-7(1)Integrity Checks15
SI-7(15)Software, Firmware, and Information Integrity | Code Authentication0
SI-7(2)Automated Notifications of Integrity Violations0
SI-7(5)Automated Response to Integrity Violations0
SI-7(7)Integration of Detection and Response11
SI-8Spam Protection12
SI-8(2)Spam Protection | Automatic Updates. Automatically update spam protection mechanisms [Assignment: organization-defined frequency]7
SR-1Policy and Procedures (SR-1)17
SR-10Inspection of Systems or Components (SR-10)8
SR-11Component Authenticity (SR-11)12
SR-11(1)Component Authenticity | Anti-counterfeit Training. Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, softwar6

Tell me when FedRAMP High files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • Log review procedures with assigned analyst owners
  • Audit log integrity controls including write once storage or hashing
  • SIEM ingestion configuration showing all in scope systems
  • Time synchronisation evidence across logging endpoints
  • Patch deployment reports across server, endpoint, and network estates
  • Patch management policy with severity based SLAs
  • Security monitoring alert tuning records
  • Endpoint detection and response coverage report

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for FedRAMP High, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition