# KSI-SVC-VRI — Validating Resource Integrity

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /ksi/ksi-svc-vri

Theme: Service Configuration (`SVC`)

## Statement

Use cryptographic methods to validate the integrity of machine-based information resources.

## NIST 800-53 controls it reaches (7)

- `CM-02 (02)` (CM) — baselines C, D
- `CM-08 (03)` (CM) — baselines C, D
- `SC-13` (SC) — baselines B, C, D
- `SC-23` (SC) — baselines C, D
- `SI-07` (SI) — baselines C, D
- `SI-07 (01)` (SI) — baselines C, D
- `SR-10` (SR) — baselines B, C, D

## Defined terms

- **Information Resource** — Has the meaning from 44 USC § 3502 (6): "information and related resources, such as personnel, equipment, funds, and information technology." This includes any aspect of the cloud service offering, both technical and managerial, including everything that makes up the business of the offering from non-machine-based information resources like organizational policies, procedures, employees, etc. to machine-based information resources like hardware, software, cloud services, code, etc.
- **Machine-Based (Information Resources)** — Any information technology information resource—including systems, processes, software, hardware, services, cloud-native capabilities, and any other such capability, component, or resource—that relies primarily on mechanical or electronic devices (i.e. computers) for operation.
- **Validation** — Confirmation through objective evidence that implemented security capabilities and related certification data are suitable for their intended FedRAMP Certification use and support the expected security outcomes for a cloud service offering.

## Default artifacts owed by every indicator

- Explanation of measures (and their objectives) that demonstrate the Key Security Indicator, or an explanation of the reason and resulting risk to customers for not having measures available for that Key Security Indicator.
- Explanation of the cycle for any measures that are implemented persistently (if applicable).
- Verification that the measures demonstrate the Key Security Indicator, or that the reason for not having them is accepted.
- Verification that the automation in place is accurate and sufficient to demonstrate appropriate measures for the Key Security Indicator, or that automation is not necessary for each measure.
- Validation that the measures are accurately produced and are in place and working as intended, or that the reason for not having them is valid.
