# KSI-IAM-JIT — Authorizing Just-in-Time

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /ksi/ksi-iam-jit

Theme: Identity and Access Management (`IAM`)

## Statement

A least-privileged, role and attribute-based, and just-in-time security authorization model is used and persistently reviewed for all user and non-user accounts and services.

## NIST 800-53 controls it reaches (38)

- `AC-02` (AC) — baselines B, C, D
- `AC-02 (01)` (AC) — baselines C, D
- `AC-02 (02)` (AC) — baselines C, D
- `AC-02 (03)` (AC) — baselines C, D
- `AC-02 (04)` (AC) — baselines C, D
- `AC-02 (06)` (AC) — in no class baseline
- `AC-03` (AC) — baselines B, C, D
- `AC-04` (AC) — baselines C, D
- `AC-05` (AC) — baselines C, D
- `AC-06` (AC) — baselines C, D
- `AC-06 (01)` (AC) — baselines C, D
- `AC-06 (02)` (AC) — baselines C, D
- `AC-06 (05)` (AC) — baselines C, D
- `AC-06 (07)` (AC) — baselines C, D
- `AC-06 (09)` (AC) — baselines C, D
- `AC-06 (10)` (AC) — baselines C, D
- `AC-07` (AC) — baselines B, C, D
- `AC-17` (AC) — baselines B, C, D
- `AC-20 (01)` (AC) — baselines C, D
- `AU-09 (04)` (AU) — baselines C, D
- `CM-05` (CM) — baselines B, C, D
- `CM-07` (CM) — baselines B, C, D
- `CM-07 (02)` (CM) — baselines C, D
- `CM-07 (05)` (CM) — baselines C, D
- `CM-09` (CM) — baselines C, D
- `IA-04` (IA) — baselines B, C, D
- `IA-04 (04)` (IA) — baselines C, D
- `IA-07` (IA) — baselines B, C, D
- `PS-02` (PS) — baselines B, C, D
- `PS-03` (PS) — baselines B, C, D
- `PS-04` (PS) — baselines B, C, D
- `PS-05` (PS) — baselines B, C, D
- `PS-06` (PS) — baselines B, C, D
- `PS-09` (PS) — baselines B, C, D
- `RA-05 (05)` (RA) — baselines C, D
- `SC-02` (SC) — baselines C, D
- `SC-23` (SC) — baselines C, D
- `SC-39` (SC) — baselines B, C, D

## Defined terms

- **Persistently** — Occurring in a firm, steady way that is repeated over a long period of time in spite of obstacles or difficulties. Persistent activities may vary between actors, may occur irregularly, and may include interruptions or waiting periods between cycles. These attributes of persistent activities should be intentional, understood, and documented; the status of persistent activities will always be known.

## Default artifacts owed by every indicator

- Explanation of measures (and their objectives) that demonstrate the Key Security Indicator, or an explanation of the reason and resulting risk to customers for not having measures available for that Key Security Indicator.
- Explanation of the cycle for any measures that are implemented persistently (if applicable).
- Verification that the measures demonstrate the Key Security Indicator, or that the reason for not having them is accepted.
- Verification that the automation in place is accurate and sufficient to demonstrate appropriate measures for the Key Security Indicator, or that automation is not necessary for each measure.
- Validation that the measures are accurately produced and are in place and working as intended, or that the reason for not having them is valid.
