Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Automationregister v0.9.0

Every control a Key Security Indicator reaches, and what this project knows about proving it from two planes — the AWS account, and the pipeline that produces what runs in it: the recipes that already collect it, the ones that are owed, the controls that close as documents against the planes read so far, and the ones nobody has assessed yet.

class

209 controls

status
legend
  • recipeAlready collecteda command is written; you run it
  • automatableA machine couldone call would settle it — nobody has written it
  • partialA machine gets part of the waythe call proves some of it; you write the rest
  • narrativeOnly a person canno AWS or pipeline API answers this — it is a document you write
  • unreviewedNobody has lookednot judged either way, by us or anyone
  • = in the class B, C and D baselines, left to right
  • AC-01In baseline B, C, Dnarrative

    An access control policy and its procedures are documents developed, disseminated and reviewed on a stated cycle; no API reports that a document exists or that anyone read it.

    Assessed against AWS.

  • AC-02In baseline B, C, Drecipeiam-account-authorization-details
  • Automated account management is a claim about the mechanism that provisions and deprovisions — Identity Center's SCIM provisioning status and its identity-source binding are readable, and that is telemetry. Whether that mechanism is the one every account in the boundary is managed by, and what it is fed from, is an architecture statement. Dropped from two recipes on 2026-08-26 whose key-age assertions were testing IA-05 (g), not this.

    Assessed against AWS.

  • AC-02 (02)In baseline C, Drecipetemporary-account-automatic-revocation
  • AC-02 (03)In baseline C, Drecipeiam-access-analyzer-unused-access
  • AC-02 (05)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • AC-02 (06)In no class baselineunreviewednobody has read this one against AWS and pipeline
  • Security groups, network ACLs, route tables, VPC endpoint policies and Network Firewall rules enumerate every flow the deployment actually permits; which flows were APPROVED is a document the enumeration is compared against.

    Assessed against AWS.

  • AC-05In baseline C, DpartialAWS IAMAWS IAM Access AnalyzerAWS Organizations

    IAM policies and Identity Center permission sets show whether any principal holds two duties at once, so the implementation is measurable; the set of duties that require separation is stated in the SSP, not in AWS.

    Assessed against AWS.

  • AC-06 (01)In baseline C, Drecipeiam-account-authorization-details
  • AC-06 (02)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • AC-06 (05)In baseline C, Drecipeidentity-center-jit-elevation-workflow
  • AC-06 (07)In baseline C, Drecipeiam-access-analyzer-unused-access
  • CloudTrail records management events by default, and every privileged control-plane call arrives as one — IAM policy writes, KMS key operations, security-group authorizations. A trail capturing read AND write management events, still logging, with log-file validation on, decides the control-plane half from its own output. The in-guest half does not close: AWS documents that Session Manager logging is unavailable for sessions connecting through port forwarding or SSH, so an operator who reaches a host that way executes privileged functions and leaves no session log while get-document still reports logging enabled, and which instances ship the auth log is a CloudWatch agent configuration living on the instance, not a field any API returns. A recipe here evidences the control plane and hands the in-guest plane to a sampled review.

    Assessed against AWS.

  • AC-06 (10)In baseline C, DpartialAWS IAMAWS IAM Access AnalyzerAWS Config

    Preventing non-privileged users from executing privileged functions needs a partition of principals into privileged and non-privileged that no IAM output carries; given the partition, the policies each side holds are enumerable and the check is writable. Dropped from config-iam-policy-no-admin-access on 2026-08-26 because the rule sees customer-managed policies only and carries no such partition.

    Assessed against AWS.

  • AC-07In baseline B, C, Drecipeguardduty-suspicious-iam-activity-response
  • AC-12In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • AC-14In baseline B, C, DpartialAWS IAM Access AnalyzerAWS ConfigAmazon S3 Block Public Access

    Access Analyzer and the public-access Config rules enumerate every path that reaches a resource without authentication; the rationale for each path that is deliberately permitted is documented.

    Assessed against AWS.

  • AC-17In baseline B, C, Dreciperemote-access-authorization-and-monitoring
  • AC-18 (01)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • AC-18 (03)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • AC-20In baseline B, C, Drecipeexternal-access-inventory-and-trust-boundary
  • AC-20 (01)In baseline C, Dnarrative

    The enhancement asks for verification that the EXTERNAL system implements the required controls, or a retained agreement saying so — a statement about somebody else's estate that no call against this one can make.

    Assessed against AWS.

  • AT-02In baseline B, C, Dnarrative

    Training delivery and completion live in a learning management system; AWS has no notion of a trained person.

    Assessed against AWS.

  • AT-02 (02)In baseline B, C, Dnarrative

    The requirement is that awareness training covers insider threat — a property of the course content, not of any system state.

    Assessed against AWS.

  • AT-02 (03)In baseline C, Dnarrative

    Same shape as the sibling enhancement: what the training covers is a property of the curriculum, which no API enumerates.

    Assessed against AWS.

  • AT-03In baseline B, C, Dnarrative

    Role-based training records map people to courses in an LMS; the AWS role a principal assumes says nothing about what they were taught.

    Assessed against AWS.

  • AT-03 (05)In no class baselinenarrative

    Whether PII-handling training was delivered is an LMS record; AWS can show where PII sits, never who was trained on it.

    Assessed against AWS.

  • AT-04In baseline B, C, Dnarrative

    Retention of individual training records is an LMS retention setting; where those records are stored could be an AWS fact, but their content and completeness never are.

    Assessed against AWS.

  • AU-02In baseline B, C, Drecipeconfig-cloudtrail-audit-logging
  • AU-03In baseline B, C, DpartialAWS CloudTrailAmazon CloudWatch Logs

    Content of audit records is a property of the record, and CloudTrail's event schema fixes the fields — type, time, source, outcome, identity — so a sample event read out of the trail proves the shape. Which additional content the organization requires, and whether application and OS logs carry the same fields, is a document. Dropped from config-cloudtrail-audit-logging on 2026-08-26: a rule that checks a multi-Region trail exists does not read a record.

    Assessed against AWS.

  • AU-03 (01)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • AU-03 (03)In no class baselineunreviewednobody has read this one against AWS and pipeline
  • AU-04In baseline B, C, Drecipeaudit-log-retention-and-delivery-failure
  • AU-05In baseline B, C, Drecipeaudit-log-retention-and-delivery-failure
  • AU-06In baseline B, C, Drecipecloudwatch-log-review-alerting
  • AU-06 (01)In baseline C, Drecipecloudwatch-log-review-alerting
  • AU-06 (03)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • AU-07In baseline C, Drecipeaudit-reduction-and-report-generation
  • AU-07 (01)In baseline C, Drecipeaudit-reduction-and-report-generation
  • AU-08In baseline B, C, Drecipeclock-synchronization-and-timestamps
  • AU-09In baseline B, C, Drecipeconfig-cloudtrail-audit-logging
  • AU-09 (04)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • AU-11In baseline B, C, Drecipeaudit-log-retention-and-delivery-failure
  • AU-12In baseline B, C, Drecipeconfig-cloudtrail-audit-logging
  • CA-02In baseline B, C, DpartialAWS Security HubAWS ConfigAmazon Inspector

    Security Hub standards and Config conformance packs perform an automated control assessment continuously and return a pass/fail per control, which is the assessment ACTIVITY; the assessment plan that fixed the scope, depth and methods, and the report that came out the other end, are documents no call returns. AWS Audit Manager is the obvious candidate and is deliberately not named — AWS has closed it to new customers, so a recipe built on it would be unfollowable advice for most readers.

    Assessed against AWS.

  • CA-02 (01)In baseline B, C, Dnarrative

    Independence is a property of the assessor, not of the assessment: who performed it, who they report to, and whether they had any hand in developing or operating the system. A 3PAO reads the independence attestation and the engagement letter; no account state distinguishes an independent assessor from an employee holding the same IAM role.

    Assessed against AWS.

  • Every external interface is enumerable — VPC peering connections, Transit Gateway attachments, PrivateLink endpoints, Direct Connect virtual interfaces and the resource policies that admit another account — so the interface characteristics the control asks to be documented are telemetry. The agreement that APPROVES each exchange is not, and the dataset's own AC-20 guidance says exactly this, differentiating CA-3 as the documented agreement between the two system owners.

    Assessed against AWS.

  • The operating half is pure telemetry: whether the Config recorder is on and recording every resource type, which Security Hub standards are enabled and their control statuses, whether Inspector and GuardDuty cover the account. The strategy the control actually names — the metrics chosen, the monitoring frequencies, who correlates and who reports — is a document, and the telemetry is what that document is measured against rather than a substitute for it.

    Assessed against AWS.

  • CA-07 (01)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CA-07 (04)In baseline B, C, DpartialAWS Security HubAWS ConfigAWS CloudTrail

    Two of the three named ingredients are collectible: compliance monitoring is Security Hub control status and a conformance pack's compliance summary, change monitoring is the Config configuration-item history joined to CloudTrail. Effectiveness monitoring — whether the risk responses in place are actually reducing risk — is the judgement, and it is the third no score substitutes for.

    Assessed against AWS.

  • CA-09In baseline B, C, Drecipeinternal-connection-inventory-and-authorization
  • CM-02In baseline B, C, Drecipessm-configuration-baseline-enforced
  • CM-02 (02)In baseline C, Drecipeconfig-asset-inventory
  • CM-02 (03)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CM-02 (07)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CM-03In baseline C, Drecipecloudtrail-config-change-history
  • CM-03 (02)In baseline C, DpartialAWS CloudFormationAWS CodePipelineAWS Config

    Three collectible artifacts line up with the three verbs: a CloudFormation change set is the validated preview of what a change would do, a pipeline execution record shows the test stage that gated the deployment and whether it passed, and an approval action on that pipeline carries who signed the change off. Change Manager would carry the approval and the runbook together, but it is one of the Systems Manager capabilities AWS lists as unavailable in the GovCloud (US) Regions, so a recipe leading with it is undeliverable for a FedRAMP estate — build on the change set and the pipeline, which exist in both partitions. Whether the tests were ADEQUATE to the change is the reviewer's judgement, and a green stage cannot report it.

    Assessed against AWS.

  • CM-03 (04)In baseline C, Drecipesecurity-representative-change-approval
  • CM-05In baseline B, C, Drecipechange-authority-restrictions-and-enforcement
  • CM-06In baseline B, C, Drecipessm-configuration-baseline-enforced
  • CM-07In baseline B, C, Drecipeconfig-least-functionality
  • CM-07 (01)In baseline C, Drecipeconfig-least-functionality
  • CM-07 (02)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CM-07 (05)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CM-08In baseline B, C, Drecipeconfig-asset-inventory
  • CM-08 (01)In baseline C, Drecipeconfig-asset-inventory
  • CM-09In baseline C, Dnarrative

    A configuration management plan is a document: it names the roles, defines what counts as a configuration item, and states how the baseline is protected from unauthorised change. AWS enforces whatever baseline it is given and reports drift from it, but the plan that decided what the baseline should be is read, never queried.

    Assessed against AWS.

  • CM-12In baseline C, Drecipeinformation-location-and-classification
  • CM-12 (01)In baseline C, Drecipeinformation-location-and-classification
  • CP-02In baseline B, C, Dnarrative

    A contingency plan is a document: developed, distributed to named roles, coordinated with related plans, reviewed on a cycle and updated after changes. A 3PAO reads the plan, its distribution list and its revision history; no API reports that a plan exists or that anyone maintains it.

    Assessed against AWS.

  • CP-02 (01)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-02 (03)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-02 (08)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-03In baseline B, C, Dnarrative

    Contingency training is delivered to people on a schedule and recorded in a training system. A 3PAO reads the curriculum, the roster and the completion dates; nothing in an AWS account changes when someone is trained.

    Assessed against AWS.

  • CP-04In baseline B, C, DpartialAWS BackupAWS Elastic Disaster RecoveryAWS Resilience Hub

    AWS Backup restore-testing plans and their job history genuinely evidence that a technical recovery test ran on a schedule, completed, and how long it took — that is more than nothing and should not be closed as narrative. What it does not cover is CP-04's subject: exercising the contingency PLAN, reviewing the results with the participants and initiating corrective actions, which is an exercise report and a remediation record.

    Assessed against AWS.

  • CP-04 (01)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-06In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-06 (01)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-06 (03)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-07In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-07 (01)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-07 (02)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-07 (03)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-08In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-08 (01)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-08 (02)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-09In baseline B, C, Drecipeconfig-data-backup-enabled
  • CP-09 (01)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-09 (08)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • CP-10In baseline B, C, Drecipebackup-restore-testing
  • CP-10 (02)In baseline C, Drecipebackup-restore-testing
  • IA-02 (01)In baseline B, C, DpartialAWS IAMAWS IAM Identity CenterAWS Config

    The credential report's mfa_active and the MFA_ENABLED_FOR_IAM_CONSOLE_ACCESS rule are TRUE for a virtual TOTP app as much as for a FIDO key, and FedRAMP's guidance on this enhancement is that the factor be phishing-resistant. list-mfa-devices discloses the device type by SerialNumber shape for IAM users, which is telemetry; whether workforce console access runs through IAM users at all, or through Identity Center and an external IdP whose factor AWS never sees, is the judgement. Re-filed here from two recipes the 2026-08-26 audit found were testing IA-02 base.

    Assessed against AWS.

  • IA-02 (02)In baseline B, C, DpartialAWS IAMAWS Config

    Same telemetry as IA-02 (01) and the same phishing-resistance judgement, with one more gap: nothing in the credential report or the Config rule partitions privileged accounts from non-privileged ones, so the enhancement's own subject — the non-privileged population — is a list a human supplies. Dropped from config-mfa-enabled-console-access on 2026-08-26 because one assertion carried both enhancements with nothing to tell them apart.

    Assessed against AWS.

  • IA-02 (08)In baseline B, C, DpartialAWS IAMAWS STSAWS IAM Identity Center

    The credential report and STS usage prove authentication runs on signed, time-bounded temporary credentials rather than long-lived secrets; replay resistance itself is a property of the SigV4 protocol, cited from AWS documentation rather than measured.

    Assessed against AWS.

  • IA-03In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • IA-04In baseline B, C, Drecipeidentifier-assignment-and-reuse-prevention
  • IA-04 (04)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • IA-05In baseline B, C, Drecipeiam-credential-reportconfig-access-keys-rotated
  • IA-05 (01)In baseline B, C, DpartialAWS IAMAWS IAM Identity Center

    get-account-password-policy returns the length, complexity, reuse and age settings this enhancement asks for, and the ODPs are numbers a recipe can carry as parameters — that half is telemetry. The organization-defined values themselves, and whether IAM users are the password population at all on an estate signing in through an external IdP, are the judgement. Dropped from iam-credential-report on 2026-08-26: access-key age is not a password rule.

    Assessed against AWS.

  • IA-05 (02)In baseline C, DpartialAWS Certificate ManagerAWS Private CAAWS KMSAWS IAM

    ACM and Private CA enumerate every certificate, its chain and its expiry, and a KMS key policy proves the private key is non-exportable; whether each relying party actually validates the full certification path is a per-application TLS client setting.

    Assessed against AWS.

  • IA-06In baseline B, C, Dnarrative

    Obscuring authentication feedback is a property of what a login interface renders; no API reports what a form displayed while someone typed into it.

    Assessed against AWS.

  • IA-07In baseline B, C, DpartialAWS KMSAWS CloudHSMAWS Config

    The same shape as SC-13, which the overlay already rates partial: KMS and CloudHSM are enumerable and the FIPS endpoints in use are checkable, but the module's FIPS 140 validation is a certificate that is cited, never measured.

    Assessed against AWS.

  • IA-08In baseline B, C, Drecipecognito-external-user-authentication
  • IA-11In baseline B, C, Drecipesession-lifetime-and-reauthentication
  • IA-12In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • IA-12 (02)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • IA-12 (03)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • IA-12 (05)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • IR-02In baseline B, C, Dnarrative

    Incident response training is delivered to responders and refreshed on a cycle. A 3PAO reads the training content, the roster of who took it and when, and any simulated-event exercise records; no AWS call reports a trained responder.

    Assessed against AWS.

  • IR-02 (03)In no class baselineunreviewednobody has read this one against AWS and pipeline
  • IR-03 (02)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • IR-05In baseline B, C, Drecipeguardduty-pattern-review-past-incidents
  • IR-06In baseline B, C, Drecipesecurityhub-incident-review-procedures
  • IR-06 (01)In baseline C, Drecipesecurityhub-incident-review-procedures
  • IR-06 (03)In baseline C, Drecipesecurityhub-incident-review-procedures
  • IR-07In baseline B, C, Drecipesecurityhub-incident-review-procedures
  • IR-07 (01)In baseline C, Drecipesecurityhub-incident-review-procedures
  • IR-08 (01)In no class baselinerecipesecurityhub-incident-review-procedures
  • MA-02In baseline B, C, DpartialAWS Systems ManagerAWS ConfigAWS CloudTrail

    Systems Manager Maintenance Windows and their execution history prove scheduled maintenance was defined, ran, and what it touched — the schedule, the tasks, the targets and the outcome of each run. The approval before the work, the review of maintenance records afterwards, and all physical maintenance and component replacement, which is AWS's responsibility, are outside that output.

    Assessed against AWS.

  • PL-08In baseline B, C, Dnarrative

    The security and privacy architecture description is a written artifact reviewed for coherence with the SSP; a resource inventory is evidence about the deployment, not about the document.

    Assessed against AWS.

  • PL-09In no class baselinepartialAWS OrganizationsAWS ConfigAWS Security HubAWS Firewall Manager

    Organizations SCPs, a Config aggregator and Security Hub central configuration prove that management IS centralized; which controls the organization chose to manage centrally is an ODP a human states.

    Assessed against AWS.

  • PL-10In baseline B, C, Dnarrative

    Selecting a control baseline is a documented decision recorded in the SSP; no API states which baseline an authorization boundary claims.

    Assessed against AWS.

  • PM-03In no class baselineunreviewednobody has read this one against AWS and pipeline
  • PM-07In no class baselineunreviewednobody has read this one against AWS and pipeline
  • PS-02In baseline B, C, Dnarrative

    Risk designations are assigned to positions in an HR system and reviewed against screening criteria; no AWS API knows what a position is.

    Assessed against AWS.

  • PS-03In baseline B, C, Dnarrative

    Background screening happens before access is granted, in an HR or vendor system; AWS sees only the principal that results.

    Assessed against AWS.

  • PS-04In baseline B, C, Drecipepersonnel-separation-access-revocation
  • PS-05In baseline B, C, Drecipepersonnel-transfer-access-reassignment
  • PS-06In baseline B, C, Dnarrative

    A signed access agreement is a document a 3PAO reads; AWS holds no signature and no acknowledgement.

    Assessed against AWS.

  • PS-07In baseline B, C, Dnarrative

    Requirements on third-party personnel live in contracts and in provider notifications of personnel changes, not in any AWS resource.

    Assessed against AWS.

  • PS-08In baseline B, C, Dnarrative

    A sanctions process is an HR procedure invoked after a violation; nothing in an AWS account records that it ran.

    Assessed against AWS.

  • PS-09In baseline B, C, Dnarrative

    Security roles and responsibilities are stated in position descriptions maintained entirely outside the system.

    Assessed against AWS.

  • RA-03 (01)In baseline B, C, Dnarrative

    A supply chain risk assessment is an analysis someone writes about suppliers, components and services and then updates as the supply chain changes. AWS Artifact supplies inputs to it — third-party attestations and audit reports — but the assessment itself is the document a 3PAO reads, and no API produces one.

    Assessed against AWS.

  • RA-05In baseline B, C, Drecipepatch-and-vulnerability-remediation
  • RA-05 (05)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • RA-05 (11)In baseline B, C, Dnarrative

    A public disclosure program is a published intake channel and a commitment to act on what arrives through it. A 3PAO reads the published policy, the disclosure page or security.txt, and the history of reports received and resolved; no AWS call reports that a reporting channel exists, let alone that anyone answered it.

    Assessed against AWS.

  • SA-02In baseline B, C, Dunreviewednobody has read this one against AWS and pipeline
  • SA-03In baseline B, C, Dnarrative

    The control asks that the system be acquired and built under a documented lifecycle, with security roles assigned and risk management integrated into each phase. None of those three is a property of the estate: a pipeline execution record names no lifecycle, assigns no role and integrates no risk decision, so it is not partial evidence of any limb — it is evidence of a different thing that happens to run alongside. The lifecycle definition, the role assignments and the phase gates live in the SSP and the acquisition record, and a 3PAO reads them there.

    Assessed against AWS.

  • SA-05In baseline B, C, Dunreviewednobody has read this one against AWS and pipeline
  • SA-08In baseline B, C, Drecipeinfrastructure-policy-scan-coverage-and-deviations
  • SA-09In baseline B, C, DpartialAWS IAM Access AnalyzerAWS IAMAmazon VPCAWS Config

    The inventory half is already collected by this overlay — Access Analyzer enumerates every external principal trusted by the estate, and that is the same enumeration the AC-20 recipe performs. That each external provider MEETS the security requirements imposed on it is a statement about somebody else's estate, captured in the agreement CA-3 names, which is why the dataset's AC-20 guidance separates the three controls in the first place.

    Assessed against AWS.

  • SA-10In baseline C, Drecipedeveloper-change-control-and-integrity
  • SA-11In baseline C, Drecipestatic-analysis-coverage-and-flaw-disposition
  • SA-15 (03)In baseline C, Dnarrative

    The control asks the developer to perform a criticality analysis at defined decision points and at a defined level of rigor. No pipeline emits one: the analysis names which components are critical to mission function, which is a judgement about the mission rather than a property of the build. A dependency graph enumerates components and ranks none of them. A 3PAO reads the criticality analysis itself and the decision points recorded in the SDLC documentation.

    Assessed against pipeline.

  • SC-02In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SC-04In baseline C, DpartialAmazon EBSAmazon EC2AWS Config

    The customer half is readable: EBS encryption-by-default, no snapshot or AMI shared beyond the account, and instance tenancy all bear on whether storage released by one workload reaches an unintended reader. The control's core — that nothing survives in memory or storage between one tenant's use of a shared resource and the next — is a hypervisor property inherited from AWS's own authorisation and read out of Artifact, never returned by a call against your account.

    Assessed against AWS.

  • SC-05In baseline B, C, Drecipeddos-protection-and-rate-limiting
  • SC-07In baseline B, C, Drecipeconfig-network-boundary-protection
  • SC-07 (03)In baseline C, Drecipeboundary-access-points-and-default-deny
  • SC-07 (04)In baseline C, Drecipeboundary-access-points-and-default-deny
  • SC-07 (05)In baseline C, Drecipeboundary-access-points-and-default-deny
  • SC-07 (07)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SC-07 (08)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SC-08In baseline B, C, Drecipeconfig-encryption-in-transit
  • Cryptographic protection in transit is a listener's SslPolicy name and a service's TLS setting, both readable per resource; FedRAMP's demand that the module be FIPS-validated is the same certificate-number limb SC-13 carries, looked up rather than returned. Dropped from config-encryption-in-transit on 2026-08-26, where no command read an SslPolicy.

    Assessed against AWS.

  • SC-10In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SC-12In baseline B, C, DpartialAWS KMSAWS CloudHSMAWS Secrets ManagerAWS Certificate ManagerAWS Config

    Generation and rotation are fields: GetKeyRotationStatus returns whether automatic rotation is enabled and its period, DescribeKey returns the origin — AWS_KMS meaning material generated inside the HSM that never leaves it — and the key policy is the access scoping written down. Destruction is not. DeletionDate is present only when a key is already scheduled for deletion and PendingDeletionWindowInDays only for a pending replica, so on an estate of healthy keys the fields an assertion would read are absent from the response and any claim about the destruction window is vacuously true; the window is a ScheduleKeyDeletion request parameter, not a key attribute. The deeper gap is the control's own wording — generation, distribution, storage, access and destruction are measured against organization-defined requirements, and this dataset carries no SC-12 parameter value, so the check compares KMS state to the SSP rather than to something in the output.

    Assessed against AWS.

  • SC-13In baseline B, C, Drecipeconfig-kms-key-management
  • SC-17In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SC-18In baseline C, Drecipemobile-code-admission-and-bundle-provenance
  • SC-20In baseline B, C, Dreciperoute53-dnssec-signing
  • SC-21In baseline B, C, Dreciperoute53-resolver-dnssec-validation
  • SC-22In baseline B, C, Drecipename-resolution-role-separation
  • SC-23In baseline C, Drecipesession-authenticity-tls-termination
  • SC-28In baseline B, C, Drecipeconfig-encryption-at-rest
  • SC-28 (01)In baseline B, C, DpartialAWS KMSAWS ConfigAmazon S3

    Key-backed encryption is readable: ENCRYPTED_VOLUMES and RDS_STORAGE_ENCRYPTED take a kmsId/kmsKeyId parameter, and GetBucketEncryption returns the SSEAlgorithm and key. The information this enhancement protects is an SSP list, and which key ownership counts as the organization's is a policy. Dropped from config-encryption-at-rest on 2026-08-26, where no key was asserted and the S3 rule could not fail.

    Assessed against AWS.

  • SC-39In baseline B, C, Dnarrative

    A separate execution domain per process is a property of the Nitro hypervisor and the guest operating system, not a setting anyone can query. A 3PAO reads AWS's own FedRAMP authorization package for the hypervisor boundary and your architecture description for the guest side; no customer-invocable API reports process isolation.

    Assessed against AWS.

  • SI-02In baseline B, C, Drecipepatch-and-vulnerability-remediation
  • SI-02 (02)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SI-03In baseline B, C, Drecipemalicious-code-protection
  • SI-04In baseline B, C, Drecipeconfig-threat-monitoring-enabled
  • SI-04 (02)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SI-04 (04)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SI-04 (05)In baseline C, Drecipesecurityhub-incident-review-procedures
  • SI-05In baseline B, C, Drecipesecurity-advisories-receipt-and-dissemination
  • SI-07In baseline C, Drecipeintegrity-verification-and-immutability
  • SI-07 (01)In baseline C, Drecipeintegrity-verification-and-immutability
  • SI-07 (07)In baseline C, Drecipebuild-provenance-attestation-verification
  • SI-08In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SI-08 (02)In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SI-10In baseline C, Drecipeinput-validation-taint-analysis-coverage
  • SI-11In baseline C, Drecipeerror-handling-information-exposure-scanning
  • SI-12In baseline B, C, DpartialAmazon CloudWatch LogsAmazon S3AWS BackupAWS Config

    Retention is set where it is enforced and every setting is readable: CloudWatch Logs retention in days, S3 lifecycle rules and Object Lock, and a Backup vault locked IN COMPLIANCE MODE, whose MinRetentionDays and MaxRetentionDays cannot be shortened by anyone, including the root user, once the grace time expires — a governance-mode lock is removable by any principal holding the IAM permission, so the mode is load-bearing rather than decorative. How long the information is REQUIRED to be kept comes from the records schedule and the law behind it, and that number arrives from outside AWS.

    Assessed against AWS.

  • SI-12 (03)In no class baselineunreviewednobody has read this one against AWS and pipeline
  • SI-16In baseline C, Dunreviewednobody has read this one against AWS and pipeline
  • SI-18 (04)In no class baselineunreviewednobody has read this one against AWS and pipeline
  • SR-02 (01)In baseline B, C, Dnarrative

    The control establishes a supply chain risk management team — organization-defined personnel, roles and responsibilities, leading defined SCRM activities. Nothing a pipeline emits evidences a team's existence or its charter. Recorded against the plan rather than silently: `docs/automation-beyond-aws.md` §P5 lists SR-02 (01) among the controls build attestation bears on, and `docs/code-scanning-overlay-plan.md` step 8 carries that into the attestation authoring batch. The control text does not support it. The attestation argument belongs to si-7.7 on its detection limb; KSI-SVC-VRI, which asks for cryptographic validation of integrity, reaches si-7 and si-7.1 instead — both already covered by an AWS partial recipe, which is where a pipeline attestation recipe would sit beside rather than replace one. A 3PAO reads the SCRM plan and the team's charter.

    Assessed against pipeline.

  • SR-05In baseline B, C, Drecipeacquisition-scanning-and-sbom-inventory
  • SR-06In baseline C, Drecipedependency-vulnerability-monitoring
  • SR-08In baseline B, C, Drecipesupply-chain-alert-notification-routing
  • SR-10In baseline B, C, Dnarrative

    Inspecting hardware for tampering is AWS's responsibility under the shared model, evidenced by its own authorization package rather than by anything you can call. The customer-side inspection — when components are examined, by whom, and what indication of need triggered it — is a documented procedure and its records, which is what a 3PAO reads.

    Assessed against AWS.

  • SR-11 (01)In baseline B, C, Dunreviewednobody has read this one against AWS and pipeline

This is the frontier register: controls a Key Security Indicator reaches and no AWS recipe collects. A control marked narrative here is not an orphan — an indicator is asking for it and you owe the evidence, in writing. The controls no indicator reaches at all are a different set, on the narrative register for class C. The two are never added together.

A control this project has assessed and not yet written a recipe for is this project’s authoring backlog — not your problem to solve by hand. What you owe is the evidence; what is missing here is our command for fetching it.

Every verdict above is this project’s authored opinion, versioned separately from the dataset: recipe rows come from the evidence overlays (AWS v3.0.0, pipeline v0.8.0) and every other row from the automation frontier register (v0.9.0). Every disposition on this page was reached against AWS and pipeline on the date the control was read, and that surface moves. The recipes themselves are on Collect; the machine-readable frontier is at /api/automation-frontier.