Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

From your scope to the commands that prove it.

Told to “collect FedRAMP evidence”? State your certification class once. Get back a scoped, copy-pasteable plan — one recipeThis product’s unit of collection, and its own coinage: an authored command, plus what one pass of it proves and how often to re-run it. for every piece of evidence your baselineThe set of controls one impact level requires. FedRAMP Rev5 publishes three, and which one binds you is the whole question of scope. owes: the command that fetches it, the cadenceHow often the rules require a piece of evidence to be refreshed. The clock on an obligation, not the command that satisfies it. the rules demand, and the controlOne numbered security requirement — AC-02, “account management” — from NIST SP 800-53, the catalogue FedRAMP draws its baselines from. it proves — plus an honest register of what no API can prove.

Two verbs: fetch (the command) and map (what it satisfies, traced to the control and to the Key Security Indicator (KSI)FedRAMP 20x’s unit of assurance: a question asked of the running system — “is MFA enforced?” — that a machine can answer, grouped into themes.that asks for it). FedRAMP 20x & Rev5, one dataset.

evidence planeA kind of question, not a vendor. The AWS plane asks a running account what it is doing; the pipeline plane asks the code and the build. — a plane is a kind of question, not a vendor

AWS
The estate itself. A running account answers questions about its own configuration — what exists, how it is set, what changed, and when.
pipeline
The system that produces the estate. Source control, CI/CD, dependency and secret scanning, static analysis, infrastructure-as-code policy checks and signed build attestations — evidence about how the estate came to be, which nothing inside the running account has ever seen.
Dataset
AWS · pipeline
AWS 51, pipeline 13by plane

Certification class

sets the scope of every screen that follows. The rules here name only classes; the Rev5 impact levelFedRAMP’s three-way sizing of a system — Low, Moderate or High — set by what the data would cost if it leaked. It picks your baseline.on each card is our reading of which one it lines up with — so if you were told only “Moderate”, you have a way in.

Targeting

drawing a target shows the size of that step below; it does not change your plan

Certification

narrows the obligations to the rules that bind that certification type

Path

a handful of subsets bind one path only; the rest bind both

Don’t know which one binds you? Compare what each class asks for, side by side.

Class A carries no Rev5 baseline — an absence, not an empty plan — so it is not offered above.

Fetch the AWS and pipeline calls

64 authored recipes with the command, the cadence and the controls a pass proves — the whole catalog, not narrowed to your class; filter by control or family there.

The three verbs

in this order, once the class is set
  1. ScopeThe whole control catalogEvery Rev5 control, the classes that bind it, and whether any indicator reaches it — narrow to your class there.409Rev5 controls
  2. PlanWhat you owe, and what automatesGrouped by indicator theme, densest first — including what no API can prove.94 of 322class C controls with a recipe
  3. CollectThe AWS and pipeline calls that fetch your evidenceCommands, expected output, assertions, GovCloud caveats, provenance.64AWS and pipeline recipes

Or start from a tool you already run

what each one proves, and what it does not
Build IAM firstclass C · densest theme

Identity and Access Management is the densest theme at class C6 indicators reaching 68 in-scope controls, 24 of them with a recipe authored on AWS. Across the plan, 64 recipes now cover 9 of 10 themes and touch 94 of 322 baseline controls.

And what you are building on that plane is mostly one thing: AWS Config is cited by 29 of the 51 AWS recipes, so the collector there is largely a Config-rule evaluator with CLI fallbacks — not 51 bespoke integrations.

Class C · IAM plan — 18 recipes ▸

narrativeNo AWS or pipeline API answers this — it is a document you write.Some evidence no API can produce — you write it. This product calls that the residueThis product’s word for what no API can produce — the writing a plan still owes. It is kept in view rather than rounded away into a coverage number., and every plan keeps it in view rather than reporting coverage it does not have. What a machine could still reach, and nobody has written yet, is the frontierThe controls an indicator reaches that no recipe covers yet — the backlog, made finite, with a judgement recorded on each rather than re-argued. below.

Frontier 151 of the 209 controls an indicator reaches now carry a verdict: 95 with an authored recipe, the rest dispositioned by hand. Authoring aims at the 122 a machine can reach — the ceiling — not at all 209; the residue above is the difference.

Every entity a permalink, every number a JSON export, everything one ⌘K away. The reference lenses live under Reference in the header.