United States

FedRAMP Moderate

323 controls. 298 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

323 controls 298 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
AC-1Policy and Procedures20
AC-11Device Lock12
AC-11(1)Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image8
AC-12Session Termination10
AC-14Permitted Actions Without Identification or Authentication3
AC-17Remote Access20
AC-17(1)Monitoring and Control13
AC-17(2)Protection of Confidentiality and Integrity Using Encryption16
AC-17(3)Managed Access Control Points16
AC-17(4)Privileged Commands and Access12
AC-18Wireless Access9
AC-18(1)Authentication and Encryption10
AC-18(3)Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployme7
AC-19Access Control for Mobile Devices16
AC-19(5)Full Device or Container-Based Encryption14
AC-2Account Management95
AC-2(1)Automated System Account Management9
AC-2(12)Account Monitoring for Atypical Usage15
AC-2(13)Disable Accounts for High-Risk Individuals13
AC-2(2)Automated Temporary and Emergency Account Management10
AC-2(3)Disable Accounts19
AC-2(4)Automated Audit Actions12
AC-2(5)Inactivity Logout12
AC-2(7)Privileged User Accounts16
AC-2(9)Restrictions on Use of Shared and Group Accounts15
AC-20Use of External Systems17
AC-20(1)Limits on Authorized Use14
AC-20(2)Portable Storage Devices Restricted Use13
AC-21Information Sharing14
AC-22Publicly Accessible Content11
AC-3Access Enforcement36
AC-4Information Flow Enforcement22
AC-4(21)Physical or Logical Separation of Information Flows15
AC-5Separation of Duties19
AC-6Least Privilege26
AC-6(1)Authorize Access to Security Functions14
AC-6(10)Prohibit Non-Privileged Users from Executing Privileged Functions15
AC-6(2)Non-Privileged Access for Nonsecurity Functions15
AC-6(5)Privileged Accounts16
AC-6(7)Review of User Privileges20
AC-6(9)Log Use of Privileged Functions14
AC-7Unsuccessful Logon Attempts14
AC-8System Use Notification5
AT-1Policy and Procedures17
AT-2Literacy Training and Awareness31
AT-2(2)Insider Threat13
AT-2(3)Social Engineering and Mining13
AT-3Role-Based Training29
AT-4Training Records19
AU-1Policy and Procedures15
AU-11Audit Record Retention16
AU-12Audit Record Generation23
AU-2Event Logging23
AU-3Content of Audit Records19
AU-3(1)Additional Audit Information12
AU-4Audit Log Storage Capacity12
AU-5Response to Audit Logging Process Failures11
AU-6Audit Record Review, Analysis, and Reporting27
AU-6(1)Automated Process Integration18
AU-6(3)Correlate Audit Record Repositories18
AU-7Audit Record Reduction and Report Generation12
AU-7(1)Automatic Processing12
AU-8Time Stamps12
AU-9Protection of Audit Information18
AU-9(4)Access by Subset of Privileged Users13
CA-1Policy and Procedures18
CA-2Control Assessments33
CA-2(1)Independent Assessors23
CA-2(3)Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organizati11
CA-3Information Exchange18
CA-5Plan of Action and Milestones30
CA-6Authorization19
CA-7Continuous Monitoring33
CA-7(1)Independent Assessment13
CA-7(4)Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring;17
CA-8Penetration Testing65
CA-8(1)Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system 14
CA-8(2)Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applic12
CA-9Internal System Connections163
CM-1Policy and Procedures13
CM-10Software Usage Restrictions17
CM-11User-Installed Software22
CM-12Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is process20
CM-12(1)Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assig11
CM-2Baseline Configuration19
CM-2(2)Automation Support for Accuracy and Currency12
CM-2(3)Retention of Previous Configurations11
CM-2(7)Configure Systems and Components for High-Risk Areas5
CM-3Configuration Change Control18
CM-3(2)Testing, Validation, and Documentation of Changes14
CM-3(4)Security and Privacy Representatives9
CM-4Impact Analyses17
CM-4(2)Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outc14
CM-5Access Restrictions for Change19
CM-5(1)Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and 14
CM-5(5)Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a product15
CM-6Configuration Settings23
CM-6(1)Automated Management, Application, and Verification16
CM-7Least Functionality20
CM-7(1)Periodic Review17
CM-7(2)Prevent Program Execution16
CM-7(5)Authorized Software Allow-by-Exception18
CM-8System Component Inventory26
CM-8(1)Updates During Installation and Removal13
CM-8(3)Automated Unauthorized Component Detection14
CM-9Configuration Management Plan14
CP-1Policy and Procedures17
CP-10System Recovery and Reconstitution21
CP-10(2)System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based7
CP-2Contingency Plan24
CP-2(1)Coordinate with Related Plans10
CP-2(3)Resume Mission and Business Functions13
CP-2(8)Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions15
CP-3Contingency Training15
CP-4Contingency Plan Testing24
CP-4(1)Coordinate with Related Plans12
CP-6Alternate Storage Site18
CP-6(1)Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to t9
CP-6(3)Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline expl5
CP-7Alternate Processing Site15
CP-7(1)Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibi6
CP-7(2)Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines 7
CP-7(3)Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requiremen6
CP-8Telecommunications Services10
CP-8(1)Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in6
CP-8(2)Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary tele9
CP-9System Backup23
CP-9(1)Testing for Reliability and Integrity19
CP-9(8)System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup informa16
IA-1Policy and Procedures13
IA-11Re-Authentication11
IA-12Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable10
IA-12(2)Identity Proofing | Identity Evidence. Require evidence of individual identification be presented to the registration authority6
IA-12(3)Identity Proofing | Identity Evidence Validation and Verification. Require that the presented identity evidence be validated and verified through [Assignment: organizational define6
IA-12(5)Identity Proofing | Address Confirmation. Require that a [Selection: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address 3
IA-2Identification and Authentication (Organizational Users)24
IA-2(1)MFA to Privileged Accounts21
IA-2(12)Acceptance of PIV Credentials5
IA-2(2)MFA to Non-Privileged Accounts19
IA-2(5)Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users t10
IA-2(6)Identification and Authentication (organizational Users) | Access to Accounts , separate Device. Implement multi-factor authentication for [Selection (one or more): local; network;11
IA-2(8)Access to Accounts Replay Resistant12
IA-3Device Identification and Authentication16
IA-4Identifier Management22
IA-4(4)Identifier Management | Identify User Status. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying 9
IA-5Authenticator Management23
IA-5(1)Password-Based Authentication19
IA-5(2)Public Key-Based Authentication11
IA-5(6)Protection of Authenticators19
IA-5(7)Authenticator Management | No Embedded Unencrypted Static Authenticators. Ensure that unencrypted static authenticators are not embedded in applications or other forms of static st13
IA-6Authentication Feedback8
IA-7Cryptographic Module Authentication10
IA-8Identification and Authentication (Non-Organizational Users)19
IA-8(1)Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies. Accept and electronically verify Personal Identity Verification-co5
IA-8(2)Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators. (a) Accept only external authenticators that are NIST-compliant; and (b) Docum5
IA-8(4)Identification and Authentication (non-organizational Users) | Use of Defined Profiles. Conform to the following profiles for identity management [Assignment: organization-defined 4
IR-1Policy and Procedures19
IR-2Incident Response Training39
IR-3Incident Response Testing23
IR-3(2)Incident Response Testing | Coordination with Related Plans. Coordinate incident response testing with organizational elements responsible for related plans12
IR-4Incident Handling68
IR-4(1)Automated Incident Handling Processes14
IR-5Incident Monitoring27
IR-6Incident Reporting31
IR-6(1)Automated Reporting13
IR-6(3)Incident Reporting | Supply Chain Coordination. Provide incident information to the provider of the product or service and other organizations involved in the supply chain or suppl11
IR-7Incident Response Assistance16
IR-7(1)Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignm10
IR-8Incident Response Plan29
IR-9Information Spillage Response. Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to informatio11
IR-9(2)Information Spillage Response | Training. Provide information spillage response training [Assignment: organization-defined frequency]6
IR-9(3)Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to car4
IR-9(4)Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [A5
MA-1Policy and Procedures8
MA-2Controlled Maintenance14
MA-3Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-define9
MA-3(1)Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications8
MA-3(2)Maintenance Tools | Inspect Media. Check media containing diagnostic and test programs for malicious code before the media are used in the system10
MA-3(3)Maintenance Tools | Prevent Unauthorized Removal. Prevent the removal of maintenance equipment containing organizational information by: (a) Verifying that there is no organization12
MA-4Nonlocal Maintenance15
MA-5Maintenance Personnel12
MA-5(1)Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clea6
MA-6Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of 7
MP-1Policy and Procedures14
MP-2Media Access13
MP-3Media Marking13
MP-4Media Storage17
MP-5Media Transport16
MP-6Media Sanitization25
MP-7Media Use13
PE-1Policy and Procedures14
PE-10Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place em6
PE-11Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate 8
PE-12Emergency Lighting5
PE-13Fire Protection10
PE-13(1)Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined p7
PE-13(2)Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-d6
PE-14Environmental Controls8
PE-15Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and know7
PE-16Delivery and Removal13
PE-17Alternate Work Site15
PE-2Physical Access Authorizations15
PE-3Physical Access Control19
PE-4Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [As9
PE-5Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the o10
PE-6Monitoring Physical Access16
PE-6(1)Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment. Monitor physical access to the facility where the system resides using physical intrusion alarms and surve10
PE-8Visitor Access Records12
PE-9Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction8
PL-1Policy and Procedures18
PL-10Baseline Selection. Select a control baseline for the system13
PL-11Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions9
PL-2System Security and Privacy Plans28
PL-4Rules of Behavior19
PL-4(1)Rules of Behavior | Social Media and External Site/application Usage Restrictions. Include in the rules of behavior, restrictions on: (a) Use of social media, social networking sit8
PL-8Security and Privacy Architectures16
PS-1Policy and Procedures14
PS-2Position Risk Designation10
PS-3Personnel Screening20
PS-3(3)Personnel Screening | Information Requiring Special Protective Measures. Verify that individuals accessing a system processing, storing, or transmitting information requiring speci9
PS-4Personnel Termination20
PS-5Personnel Transfer18
PS-6Access Agreements15
PS-7External Personnel Security19
PS-8Personnel Sanctions12
PS-9Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions22
RA-1Policy and Procedures86
RA-2Security Categorization28
RA-3Risk Assessment33
RA-3(1)Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; an17
RA-5Vulnerability Monitoring and Scanning28
RA-5(11)Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and syste8
RA-5(2)Update Vulnerabilities to be Scanned15
RA-5(3)Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage14
RA-5(5)Privileged Access10
RA-9Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or sy18
SA-1Policy and Procedures18
SA-10Developer Configuration Management13
SA-11Developer Testing and Evaluation19
SA-11(1)Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify c13
SA-11(2)Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling a12
SA-15Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitl16
SA-15(3)Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At6
SA-2Allocation of Resources11
SA-22Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the fo18
SA-3System Development Life Cycle21
SA-4Acquisition Process22
SA-4(1)Acquisition Process | Functional Properties of Controls. Require the developer of the system, system component, or system service to provide a description of the functional propert5
SA-4(10)Use of Approved PIV Products3
SA-4(2)Acquisition Process | Design and Implementation Information for Controls. Require the developer of the system, system component, or system service to provide design and implementat5
SA-4(9)Acquisition Process | Functions, Ports, Protocols, and Services in Use. Require the developer of the system, system component, or system service to identify the functions, ports, p7
SA-5System Documentation13
SA-8Security and Privacy Engineering Principles19
SA-9External System Services30
SA-9(1)External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information se17
SA-9(2)Identification of Functions, Ports, Protocols, and Services9
SA-9(5)External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system service16
SC-1Policy and Procedures13
SC-10Network Disconnect10
SC-12Cryptographic Key Establishment and Management15
SC-13Cryptographic Protection22
SC-15Collaborative Computing Devices and Applications5
SC-17Public Key Infrastructure Certificates9
SC-18Mobile Code12
SC-2Separation of System and User Functionality13
SC-20Secure Name/Address Resolution Service (Authoritative)5
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)6
SC-22Architecture and Provisioning for Name/Address Resolution Service5
SC-23Session Authenticity17
SC-28Protection of Information at Rest23
SC-28(1)Cryptographic Protection16
SC-39Process Isolation9
SC-4Information in Shared System Resources11
SC-45System Time Synchronization. Synchronize system clocks within and between systems and system components13
SC-45(1)System Time Synchronization | Synchronization with Authoritative Time Source. (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: 9
SC-5Denial-of-Service Protection15
SC-7Boundary Protection25
SC-7(12)Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system comp13
SC-7(18)Boundary Protection | Fail Secure. Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device4
SC-7(3)Access Points17
SC-7(4)External Telecommunications Services13
SC-7(5)Deny by Default Allow by Exception17
SC-7(7)Split Tunneling for Remote Devices8
SC-7(8)Route Traffic to Authenticated Proxy Servers17
SC-8Transmission Confidentiality and Integrity26
SC-8(1)Cryptographic Protection20
SI-1Policy and Procedures14
SI-10Information Input Validation13
SI-11Error Handling6
SI-12Information Management and Retention26
SI-16Memory Protection8
SI-2Flaw Remediation26
SI-2(2)Automated Flaw Remediation Status14
SI-2(3)Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the follo15
SI-3Malicious Code Protection25
SI-4System Monitoring24
SI-4(1)System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system13
SI-4(16)System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system12
SI-4(18)System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to de16
SI-4(2)Automated Tools and Mechanisms for Real-Time Analysis14
SI-4(23)System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-13
SI-4(4)Inbound and Outbound Communications Traffic14
SI-4(5)System-Generated Alerts14
SI-5Security Alerts, Advisories, and Directives23
SI-6Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the10
SI-7Software, Firmware, and Information Integrity18
SI-7(1)Integrity Checks15
SI-7(7)Integration of Detection and Response11
SI-8Spam Protection12
SI-8(2)Spam Protection | Automatic Updates. Automatically update spam protection mechanisms [Assignment: organization-defined frequency]7
SR-1Policy and Procedures (SR-1)17
SR-10Inspection of Systems or Components (SR-10)8
SR-11Component Authenticity (SR-11)12
SR-11(1)Component Authenticity | Anti-counterfeit Training. Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, softwar6
SR-11(2)Component Authenticity | Configuration Control for Component Service and Repair. Maintain configuration control over the following system components awaiting service or repair and 7
SR-12Component Disposal (SR-12)16
SR-2Supply Chain Risk Management Plan (SR-2)18
SR-2(1)Supply Chain Risk Management Plan | Establish SCRM Team. Establish a supply chain risk management team consisting of [Assignment: organization-defined personnel, roles, and respons8
SR-3Supply Chain Controls and Processes (SR-3)27
SR-5Acquisition Strategies, Tools, and Methods (SR-5)20
SR-6Supplier Assessments and Reviews (SR-6)26
SR-8Notification Agreements (SR-8)15
RA-7Risk Response19

Tell me when FedRAMP Moderate files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Audit and accountability policy with retention periods defined
  • List of auditable events and log source inventory
  • Log review procedures with assigned analyst owners
  • Audit log integrity controls including write once storage or hashing
  • SIEM ingestion configuration showing all in scope systems
  • Time synchronisation evidence across logging endpoints
  • Patch deployment reports across server, endpoint, and network estates
  • Patch management policy with severity based SLAs
  • Security monitoring alert tuning records
  • Endpoint detection and response coverage report

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for FedRAMP Moderate, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition