Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Control index

Accounts with privileged access are disabled or otherwise secured in response to suspicious activity.

Mapped NIST 800-53 controls (7)

  • recipe5
  • KSI only2

The mark says whether an authored AWS recipe fetches evidence for the control; the tier strip shows which Rev5 baselines also require it — where automated KSI evidence doubles as Rev5 control evidence. = in the class B, C and D baselines, left to right

  • recipean authored recipe collects evidence for this control
  • KSI onlya Key Security Indicator reaches it, but no recipe is authored yet
  • orphanno Key Security Indicator reaches it — a person writes it up instead

Collect evidence (1)

Authored AWS recipes whose output is evidence for KSI-IAM-SUS. This mapping is this project’s opinion (overlay v3.0.0), versioned separately from the dataset — the upstream FedRAMP rules name none of these tools.

Default evidence owed by every indicator (5)

From info.default_artifacts.KSI — no indicator carries its own artifacts; requirement-specific evidence lives on /evidence.

  • Explanation of measures (and their objectives) that demonstrate the Key Security Indicator, or an explanation of the reason and resulting risk to customers for not having measures available for that Key Security Indicator.
  • Explanation of the cycle for any measures that are implemented persistently (if applicable).
  • Verification that the measures demonstrate the Key Security Indicator, or that the reason for not having them is accepted.
  • Verification that the automation in place is accurate and sufficient to demonstrate appropriate measures for the Key Security Indicator, or that automation is not necessary for each measure.
  • Validation that the measures are accurately produced and are in place and working as intended, or that the reason for not having them is valid.

Defined terms used (1)

Vulnerability Response
The systematic process of tracking, evaluating, mitigating, monitoring, remediating, assessing exploitation, reporting, and otherwise managing detected vulnerabilities.

The Identity and Access Management run (6)

6/6 have an authored AWS recipe