{"dataset_version":"2026.07.14.01","last_updated":"2026-07-14","slice":"class-overview","contract_version":"1.0.0","license":{"spdx":"CC-BY-4.0","url":"https://creativecommons.org/licenses/by/4.0/","covers":"The DATA in this response (derived slices and authored overlays). The site code is not licensed by it.","attribution":"ramprules.com"},"data":{"info":{"title":"FedRAMP Consolidated Rules for 2026","version":"2026.07.14.01","lastUpdated":"2026-07-14"},"themeCount":10,"indicatorCount":46,"ksiControlCount":209,"authoredMethodCount":64,"quotaUnit":{"primary":"indicator","basis":"The rules never say whether “each Key Security Indicator” means one of the 10 themes or one of the 46 indicators. FedRAMP’s own schema names the 46 “ksi_indicator” and the 10 “ksi_theme”, so the indicator is the reading published here — with the theme reading shown beside it, because the two are 4.6× apart and no automation number means anything without its unit.","phrase":"for each Key Security Indicator"},"classes":[{"class":"a","interpretedLevel":null,"hasBaseline":false,"baselineCount":null,"coveredCount":null,"orphanCount":null,"coveragePercent":null,"annualAssessmentCount":null,"quota":{"requirementId":"FRC-CSX-VVK","requirementName":"Automated Verification and Validation of Key Security Indicators","force":"MAY","statement":"Providers seeking 20x Class A Certification MAY implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators.","minPerKsi":null,"minTotalByTheme":null,"minTotalByIndicator":null},"metrics":{"requirementId":"FRC-CSX-MOT","requirementName":"Metrics Over Time for Key Security Indicators","force":"MAY","statement":"Providers seeking 20x Class A Certification MAY supply historical metrics for Key Security Indicators."},"themes":[{"themeId":"KSI-CED","themeKey":"CED","themeName":"Cybersecurity Education","authoredMethods":0,"fullyAutomated":0,"meetsQuota":null},{"themeId":"KSI-CMT","themeKey":"CMT","themeName":"Change Management","authoredMethods":10,"fullyAutomated":0,"meetsQuota":null},{"themeId":"KSI-CNA","themeKey":"CNA","themeName":"Cloud Native Architecture","authoredMethods":10,"fullyAutomated":0,"meetsQuota":null},{"themeId":"KSI-IAM","themeKey":"IAM","themeName":"Identity and Access Management","authoredMethods":18,"fullyAutomated":0,"meetsQuota":null},{"themeId":"KSI-INR","themeKey":"INR","themeName":"Incident Response","authoredMethods":3,"fullyAutomated":0,"meetsQuota":null},{"themeId":"KSI-MLA","themeKey":"MLA","themeName":"Monitoring, Logging, and Auditing","authoredMethods":9,"fullyAutomated":0,"meetsQuota":null},{"themeId":"KSI-PIY","themeKey":"PIY","themeName":"Policy and Inventory","authoredMethods":5,"fullyAutomated":0,"meetsQuota":null},{"themeId":"KSI-RPL","themeKey":"RPL","themeName":"Recovery Planning","authoredMethods":2,"fullyAutomated":0,"meetsQuota":null},{"themeId":"KSI-SCR","themeKey":"SCR","themeName":"Supply Chain Risk","authoredMethods":11,"fullyAutomated":0,"meetsQuota":null},{"themeId":"KSI-SVC","themeKey":"SVC","themeName":"Service Configuration","authoredMethods":17,"fullyAutomated":0,"meetsQuota":null}],"themesMeetingQuota":null,"indicators":[{"indicatorId":"KSI-CED-RAT","themeKey":"CED","name":"Reviewing All Training","authoredMethods":0,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CMT-LMC","themeKey":"CMT","name":"Logging Changes","authoredMethods":3,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CMT-RMV","themeKey":"CMT","name":"Redeploying vs Modifying","authoredMethods":6,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CMT-RVP","themeKey":"CMT","name":"Reviewing Change Procedures","authoredMethods":2,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CMT-VTD","themeKey":"CMT","name":"Validating Throughout Deployment","authoredMethods":3,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CNA-DFP","themeKey":"CNA","name":"Defining Functionality and Privileges","authoredMethods":1,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CNA-IBP","themeKey":"CNA","name":"Implementing Best Practices","authoredMethods":1,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CNA-MAT","themeKey":"CNA","name":"Minimizing Attack Surface","authoredMethods":3,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CNA-OFA","themeKey":"CNA","name":"Optimizing for Availability","authoredMethods":0,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CNA-RNT","themeKey":"CNA","name":"Restricting Network Traffic","authoredMethods":2,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CNA-RVP","themeKey":"CNA","name":"Reviewing Protections","authoredMethods":1,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-CNA-ULN","themeKey":"CNA","name":"Using Logical Networking","authoredMethods":3,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-IAM-AAM","themeKey":"IAM","name":"Automating Account Management","authoredMethods":3,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-IAM-APM","themeKey":"IAM","name":"Adopting Passwordless Methods","authoredMethods":5,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-IAM-ELP","themeKey":"IAM","name":"Ensuring Least Privilege","authoredMethods":11,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-IAM-JIT","themeKey":"IAM","name":"Authorizing Just-in-Time","authoredMethods":4,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-IAM-SNU","themeKey":"IAM","name":"Securing Non-User Authentication","authoredMethods":2,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-IAM-SUS","themeKey":"IAM","name":"Responding to Suspicious Activity","authoredMethods":1,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-INR-AAR","themeKey":"INR","name":"Generating After Action Reports","authoredMethods":1,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-INR-RIR","themeKey":"INR","name":"Reviewing Incident Response Procedures","authoredMethods":1,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-INR-RPI","themeKey":"INR","name":"Reviewing Past Incidents","authoredMethods":1,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-MLA-EVC","themeKey":"MLA","name":"Evaluating Configurations","authoredMethods":2,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-MLA-LET","themeKey":"MLA","name":"Logging Event Types","authoredMethods":3,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-MLA-OSM","themeKey":"MLA","name":"Operating SIEM Capability","authoredMethods":4,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-MLA-RVL","themeKey":"MLA","name":"Reviewing Logs","authoredMethods":2,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-PIY-GIV","themeKey":"PIY","name":"Generating Inventories","authoredMethods":2,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-PIY-RES","themeKey":"PIY","name":"Reviewing Executive Support","authoredMethods":0,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-PIY-RIS","themeKey":"PIY","name":"Reviewing Investments in Security","authoredMethods":0,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-PIY-RSD","themeKey":"PIY","name":"Reviewing Security in the SDLC","authoredMethods":3,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-PIY-RVD","themeKey":"PIY","name":"Reviewing Vulnerability Disclosures","authoredMethods":0,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-RPL-ABO","themeKey":"RPL","name":"Aligning Backups with Objectives","authoredMethods":2,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-RPL-ARP","themeKey":"RPL","name":"Aligning Recovery Plan","authoredMethods":1,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-RPL-RRO","themeKey":"RPL","name":"Reviewing Recovery Objectives","authoredMethods":1,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-RPL-TRC","themeKey":"RPL","name":"Testing Recovery Capabilities","authoredMethods":1,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-SCR-MIT","themeKey":"SCR","name":"Mitigating Supply Chain Risk","authoredMethods":8,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-SCR-MON","themeKey":"SCR","name":"Monitoring Supply Chain Risk","authoredMethods":5,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-SVC-ACM","themeKey":"SVC","name":"Automating Configuration Management","authoredMethods":2,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-SVC-ASM","themeKey":"SVC","name":"Automating Secret Management","authoredMethods":2,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-SVC-EIS","themeKey":"SVC","name":"Evaluating and Improving Security","authoredMethods":4,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-SVC-SIN","themeKey":"SVC","name":"Securing Information","authoredMethods":7,"fullyAutomated":0,"meetsQuota":null},{"indicatorId":"KSI-SVC-VRI","themeKey":"SVC","name":"Validating Resource Integrity","authoredMethods":3,"fullyAutomated":0,"meetsQuota":null}],"indicatorsMeetingQuota":null},{"class":"b","interpretedLevel":"Low","hasBaseline":true,"baselineCount":155,"coveredCount":95,"orphanCount":60,"coveragePercent":61.29032258064516,"annualAssessmentCount":35,"quota":{"requirementId":"FRC-CSX-VVK","requirementName":"Automated Verification and Validation of Key Security Indicators","force":"SHOULD","statement":"Providers seeking 20x Class B Certification SHOULD implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 1 automated method for each Key Security Indicator.","minPerKsi":1,"minTotalByTheme":10,"minTotalByIndicator":46},"metrics":{"requirementId":"FRC-CSX-MOT","requirementName":"Metrics Over Time for Key Security Indicators","force":"SHOULD","statement":"Providers seeking 20x Class B Certification SHOULD supply historical metrics for Key Security Indicators."},"themes":[{"themeId":"KSI-CED","themeKey":"CED","themeName":"Cybersecurity Education","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"themeId":"KSI-CMT","themeKey":"CMT","themeName":"Change Management","authoredMethods":10,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-CNA","themeKey":"CNA","themeName":"Cloud Native Architecture","authoredMethods":10,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-IAM","themeKey":"IAM","themeName":"Identity and Access Management","authoredMethods":18,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-INR","themeKey":"INR","themeName":"Incident Response","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-MLA","themeKey":"MLA","themeName":"Monitoring, Logging, and Auditing","authoredMethods":9,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-PIY","themeKey":"PIY","themeName":"Policy and Inventory","authoredMethods":5,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-RPL","themeKey":"RPL","themeName":"Recovery Planning","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-SCR","themeKey":"SCR","themeName":"Supply Chain Risk","authoredMethods":11,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-SVC","themeKey":"SVC","themeName":"Service Configuration","authoredMethods":17,"fullyAutomated":0,"meetsQuota":true}],"themesMeetingQuota":9,"indicators":[{"indicatorId":"KSI-CED-RAT","themeKey":"CED","name":"Reviewing All Training","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CMT-LMC","themeKey":"CMT","name":"Logging Changes","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CMT-RMV","themeKey":"CMT","name":"Redeploying vs Modifying","authoredMethods":6,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CMT-RVP","themeKey":"CMT","name":"Reviewing Change Procedures","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CMT-VTD","themeKey":"CMT","name":"Validating Throughout Deployment","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CNA-DFP","themeKey":"CNA","name":"Defining Functionality and Privileges","authoredMethods":1,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CNA-EIS","themeKey":"CNA","name":"Enforcing Intended State","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-IBP","themeKey":"CNA","name":"Implementing Best Practices","authoredMethods":1,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CNA-MAT","themeKey":"CNA","name":"Minimizing Attack Surface","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CNA-OFA","themeKey":"CNA","name":"Optimizing for Availability","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-RNT","themeKey":"CNA","name":"Restricting Network Traffic","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CNA-RVP","themeKey":"CNA","name":"Reviewing Protections","authoredMethods":1,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CNA-ULN","themeKey":"CNA","name":"Using Logical Networking","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-AAM","themeKey":"IAM","name":"Automating Account Management","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-APM","themeKey":"IAM","name":"Adopting Passwordless Methods","authoredMethods":5,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-ELP","themeKey":"IAM","name":"Ensuring Least Privilege","authoredMethods":11,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-JIT","themeKey":"IAM","name":"Authorizing Just-in-Time","authoredMethods":4,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-SNU","themeKey":"IAM","name":"Securing Non-User Authentication","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-SUS","themeKey":"IAM","name":"Responding to Suspicious Activity","authoredMethods":1,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-INR-AAR","themeKey":"INR","name":"Generating After Action Reports","authoredMethods":1,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-INR-RIR","themeKey":"INR","name":"Reviewing Incident Response Procedures","authoredMethods":1,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-INR-RPI","themeKey":"INR","name":"Reviewing Past Incidents","authoredMethods":1,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-MLA-ALA","themeKey":"MLA","name":"Authorizing Log Access","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-MLA-EVC","themeKey":"MLA","name":"Evaluating Configurations","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-MLA-LET","themeKey":"MLA","name":"Logging Event Types","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-MLA-OSM","themeKey":"MLA","name":"Operating SIEM Capability","authoredMethods":4,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-MLA-RVL","themeKey":"MLA","name":"Reviewing Logs","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-PIY-GIV","themeKey":"PIY","name":"Generating Inventories","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-PIY-RES","themeKey":"PIY","name":"Reviewing Executive Support","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-PIY-RIS","themeKey":"PIY","name":"Reviewing Investments in Security","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-PIY-RSD","themeKey":"PIY","name":"Reviewing Security in the SDLC","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-PIY-RVD","themeKey":"PIY","name":"Reviewing Vulnerability Disclosures","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-RPL-ABO","themeKey":"RPL","name":"Aligning Backups with Objectives","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-RPL-ARP","themeKey":"RPL","name":"Aligning Recovery Plan","authoredMethods":1,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-RPL-RRO","themeKey":"RPL","name":"Reviewing Recovery Objectives","authoredMethods":1,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-RPL-TRC","themeKey":"RPL","name":"Testing Recovery Capabilities","authoredMethods":1,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SCR-MIT","themeKey":"SCR","name":"Mitigating Supply Chain Risk","authoredMethods":8,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SCR-MON","themeKey":"SCR","name":"Monitoring Supply Chain Risk","authoredMethods":5,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-ACM","themeKey":"SVC","name":"Automating Configuration Management","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-ASM","themeKey":"SVC","name":"Automating Secret Management","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-EIS","themeKey":"SVC","name":"Evaluating and Improving Security","authoredMethods":4,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-PRR","themeKey":"SVC","name":"Preventing Residual Risk","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-SVC-RUD","themeKey":"SVC","name":"Removing Unwanted Data","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-SVC-SIN","themeKey":"SVC","name":"Securing Information","authoredMethods":7,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-VCM","themeKey":"SVC","name":"Validating Communications","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-VRI","themeKey":"SVC","name":"Validating Resource Integrity","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true}],"indicatorsMeetingQuota":37},{"class":"c","interpretedLevel":"Moderate","hasBaseline":true,"baselineCount":322,"coveredCount":199,"orphanCount":123,"coveragePercent":61.80124223602485,"annualAssessmentCount":80,"quota":{"requirementId":"FRC-CSX-VVK","requirementName":"Automated Verification and Validation of Key Security Indicators","force":"MUST","statement":"Providers seeking 20x Class C Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 2 automated methods for each Key Security Indicator.","minPerKsi":2,"minTotalByTheme":20,"minTotalByIndicator":92},"metrics":{"requirementId":"FRC-CSX-MOT","requirementName":"Metrics Over Time for Key Security Indicators","force":"MUST","statement":"Providers seeking 20x Class C Certification MUST supply historical metrics including status from persistent validation over at least the past 6 months for all Key Security Indicators."},"themes":[{"themeId":"KSI-CED","themeKey":"CED","themeName":"Cybersecurity Education","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"themeId":"KSI-CMT","themeKey":"CMT","themeName":"Change Management","authoredMethods":10,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-CNA","themeKey":"CNA","themeName":"Cloud Native Architecture","authoredMethods":10,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-IAM","themeKey":"IAM","themeName":"Identity and Access Management","authoredMethods":18,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-INR","themeKey":"INR","themeName":"Incident Response","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-MLA","themeKey":"MLA","themeName":"Monitoring, Logging, and Auditing","authoredMethods":9,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-PIY","themeKey":"PIY","themeName":"Policy and Inventory","authoredMethods":5,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-RPL","themeKey":"RPL","themeName":"Recovery Planning","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-SCR","themeKey":"SCR","themeName":"Supply Chain Risk","authoredMethods":11,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-SVC","themeKey":"SVC","themeName":"Service Configuration","authoredMethods":17,"fullyAutomated":0,"meetsQuota":true}],"themesMeetingQuota":9,"indicators":[{"indicatorId":"KSI-CED-RAT","themeKey":"CED","name":"Reviewing All Training","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CMT-LMC","themeKey":"CMT","name":"Logging Changes","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CMT-RMV","themeKey":"CMT","name":"Redeploying vs Modifying","authoredMethods":6,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CMT-RVP","themeKey":"CMT","name":"Reviewing Change Procedures","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CMT-VTD","themeKey":"CMT","name":"Validating Throughout Deployment","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CNA-DFP","themeKey":"CNA","name":"Defining Functionality and Privileges","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-EIS","themeKey":"CNA","name":"Enforcing Intended State","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-IBP","themeKey":"CNA","name":"Implementing Best Practices","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-MAT","themeKey":"CNA","name":"Minimizing Attack Surface","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CNA-OFA","themeKey":"CNA","name":"Optimizing for Availability","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-RNT","themeKey":"CNA","name":"Restricting Network Traffic","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CNA-RVP","themeKey":"CNA","name":"Reviewing Protections","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-ULN","themeKey":"CNA","name":"Using Logical Networking","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-AAM","themeKey":"IAM","name":"Automating Account Management","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-APM","themeKey":"IAM","name":"Adopting Passwordless Methods","authoredMethods":5,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-ELP","themeKey":"IAM","name":"Ensuring Least Privilege","authoredMethods":11,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-JIT","themeKey":"IAM","name":"Authorizing Just-in-Time","authoredMethods":4,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-SNU","themeKey":"IAM","name":"Securing Non-User Authentication","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-SUS","themeKey":"IAM","name":"Responding to Suspicious Activity","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-INR-AAR","themeKey":"INR","name":"Generating After Action Reports","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-INR-RIR","themeKey":"INR","name":"Reviewing Incident Response Procedures","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-INR-RPI","themeKey":"INR","name":"Reviewing Past Incidents","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-MLA-ALA","themeKey":"MLA","name":"Authorizing Log Access","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-MLA-EVC","themeKey":"MLA","name":"Evaluating Configurations","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-MLA-LET","themeKey":"MLA","name":"Logging Event Types","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-MLA-OSM","themeKey":"MLA","name":"Operating SIEM Capability","authoredMethods":4,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-MLA-RVL","themeKey":"MLA","name":"Reviewing Logs","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-PIY-GIV","themeKey":"PIY","name":"Generating Inventories","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-PIY-RES","themeKey":"PIY","name":"Reviewing Executive Support","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-PIY-RIS","themeKey":"PIY","name":"Reviewing Investments in Security","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-PIY-RSD","themeKey":"PIY","name":"Reviewing Security in the SDLC","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-PIY-RVD","themeKey":"PIY","name":"Reviewing Vulnerability Disclosures","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-RPL-ABO","themeKey":"RPL","name":"Aligning Backups with Objectives","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-RPL-ARP","themeKey":"RPL","name":"Aligning Recovery Plan","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-RPL-RRO","themeKey":"RPL","name":"Reviewing Recovery Objectives","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-RPL-TRC","themeKey":"RPL","name":"Testing Recovery Capabilities","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-SCR-MIT","themeKey":"SCR","name":"Mitigating Supply Chain Risk","authoredMethods":8,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SCR-MON","themeKey":"SCR","name":"Monitoring Supply Chain Risk","authoredMethods":5,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-ACM","themeKey":"SVC","name":"Automating Configuration Management","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-ASM","themeKey":"SVC","name":"Automating Secret Management","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-EIS","themeKey":"SVC","name":"Evaluating and Improving Security","authoredMethods":4,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-PRR","themeKey":"SVC","name":"Preventing Residual Risk","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-SVC-RUD","themeKey":"SVC","name":"Removing Unwanted Data","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-SVC-SIN","themeKey":"SVC","name":"Securing Information","authoredMethods":7,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-VCM","themeKey":"SVC","name":"Validating Communications","authoredMethods":2,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-VRI","themeKey":"SVC","name":"Validating Resource Integrity","authoredMethods":3,"fullyAutomated":0,"meetsQuota":true}],"indicatorsMeetingQuota":27},{"class":"d","interpretedLevel":"High","hasBaseline":true,"baselineCount":409,"coveredCount":199,"orphanCount":210,"coveragePercent":48.655256723716384,"annualAssessmentCount":101,"quota":{"requirementId":"FRC-CSX-VVK","requirementName":"Automated Verification and Validation of Key Security Indicators","force":"MUST","statement":"Providers seeking 20x Class D Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 4 automated methods for each Key Security Indicator.","minPerKsi":4,"minTotalByTheme":40,"minTotalByIndicator":164},"metrics":{"requirementId":"FRC-CSX-MOT","requirementName":"Metrics Over Time for Key Security Indicators","force":"MUST","statement":"Providers seeking 20x Class D Certification MUST provide historical metrics including status from persistent validation over at least the past 18 months for all Key Security Indicators."},"themes":[{"themeId":"KSI-CED","themeKey":"CED","themeName":"Cybersecurity Education","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"themeId":"KSI-CMT","themeKey":"CMT","themeName":"Change Management","authoredMethods":10,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-CNA","themeKey":"CNA","themeName":"Cloud Native Architecture","authoredMethods":10,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-IAM","themeKey":"IAM","themeName":"Identity and Access Management","authoredMethods":18,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-INR","themeKey":"INR","themeName":"Incident Response","authoredMethods":3,"fullyAutomated":0,"meetsQuota":false},{"themeId":"KSI-MLA","themeKey":"MLA","themeName":"Monitoring, Logging, and Auditing","authoredMethods":9,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-PIY","themeKey":"PIY","themeName":"Policy and Inventory","authoredMethods":5,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-RPL","themeKey":"RPL","themeName":"Recovery Planning","authoredMethods":2,"fullyAutomated":0,"meetsQuota":false},{"themeId":"KSI-SCR","themeKey":"SCR","themeName":"Supply Chain Risk","authoredMethods":11,"fullyAutomated":0,"meetsQuota":true},{"themeId":"KSI-SVC","themeKey":"SVC","themeName":"Service Configuration","authoredMethods":17,"fullyAutomated":0,"meetsQuota":true}],"themesMeetingQuota":7,"indicators":[{"indicatorId":"KSI-CED-RAT","themeKey":"CED","name":"Reviewing All Training","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CMT-LMC","themeKey":"CMT","name":"Logging Changes","authoredMethods":3,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CMT-RMV","themeKey":"CMT","name":"Redeploying vs Modifying","authoredMethods":6,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-CMT-RVP","themeKey":"CMT","name":"Reviewing Change Procedures","authoredMethods":2,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CMT-VTD","themeKey":"CMT","name":"Validating Throughout Deployment","authoredMethods":3,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-DFP","themeKey":"CNA","name":"Defining Functionality and Privileges","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-IBP","themeKey":"CNA","name":"Implementing Best Practices","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-MAT","themeKey":"CNA","name":"Minimizing Attack Surface","authoredMethods":3,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-OFA","themeKey":"CNA","name":"Optimizing for Availability","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-RNT","themeKey":"CNA","name":"Restricting Network Traffic","authoredMethods":2,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-RVP","themeKey":"CNA","name":"Reviewing Protections","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-CNA-ULN","themeKey":"CNA","name":"Using Logical Networking","authoredMethods":3,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-IAM-AAM","themeKey":"IAM","name":"Automating Account Management","authoredMethods":3,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-IAM-APM","themeKey":"IAM","name":"Adopting Passwordless Methods","authoredMethods":5,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-ELP","themeKey":"IAM","name":"Ensuring Least Privilege","authoredMethods":11,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-JIT","themeKey":"IAM","name":"Authorizing Just-in-Time","authoredMethods":4,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-IAM-SNU","themeKey":"IAM","name":"Securing Non-User Authentication","authoredMethods":2,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-IAM-SUS","themeKey":"IAM","name":"Responding to Suspicious Activity","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-INR-AAR","themeKey":"INR","name":"Generating After Action Reports","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-INR-RIR","themeKey":"INR","name":"Reviewing Incident Response Procedures","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-INR-RPI","themeKey":"INR","name":"Reviewing Past Incidents","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-MLA-EVC","themeKey":"MLA","name":"Evaluating Configurations","authoredMethods":2,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-MLA-LET","themeKey":"MLA","name":"Logging Event Types","authoredMethods":3,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-MLA-OSM","themeKey":"MLA","name":"Operating SIEM Capability","authoredMethods":4,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-MLA-RVL","themeKey":"MLA","name":"Reviewing Logs","authoredMethods":2,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-PIY-GIV","themeKey":"PIY","name":"Generating Inventories","authoredMethods":2,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-PIY-RES","themeKey":"PIY","name":"Reviewing Executive Support","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-PIY-RIS","themeKey":"PIY","name":"Reviewing Investments in Security","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-PIY-RSD","themeKey":"PIY","name":"Reviewing Security in the SDLC","authoredMethods":3,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-PIY-RVD","themeKey":"PIY","name":"Reviewing Vulnerability Disclosures","authoredMethods":0,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-RPL-ABO","themeKey":"RPL","name":"Aligning Backups with Objectives","authoredMethods":2,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-RPL-ARP","themeKey":"RPL","name":"Aligning Recovery Plan","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-RPL-RRO","themeKey":"RPL","name":"Reviewing Recovery Objectives","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-RPL-TRC","themeKey":"RPL","name":"Testing Recovery Capabilities","authoredMethods":1,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-SCR-MIT","themeKey":"SCR","name":"Mitigating Supply Chain Risk","authoredMethods":8,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SCR-MON","themeKey":"SCR","name":"Monitoring Supply Chain Risk","authoredMethods":5,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-ACM","themeKey":"SVC","name":"Automating Configuration Management","authoredMethods":2,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-SVC-ASM","themeKey":"SVC","name":"Automating Secret Management","authoredMethods":2,"fullyAutomated":0,"meetsQuota":false},{"indicatorId":"KSI-SVC-EIS","themeKey":"SVC","name":"Evaluating and Improving Security","authoredMethods":4,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-SIN","themeKey":"SVC","name":"Securing Information","authoredMethods":7,"fullyAutomated":0,"meetsQuota":true},{"indicatorId":"KSI-SVC-VRI","themeKey":"SVC","name":"Validating Resource Integrity","authoredMethods":3,"fullyAutomated":0,"meetsQuota":false}],"indicatorsMeetingQuota":9}]}}