Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Two vocabularies, one join

NIST 800-53 controls and FedRAMP Key Security Indicators are different objects that join. Walk the join in both directions before anything else, because every later claim traverses it.

Rendered from FedRAMP Consolidated Rules for 2026 version 2026.07.14.01

A control is a requirement written for an organisation: account management, boundary protection, developer testing. A Key Security Indicator is an outcome statement written for continuous proof: “modifications to the cloud service offering are logged and monitored.” They are different objects, in different documents, with different grammars — and they join.

The join reads in one direction: an indicator names the controls it is evidence for. Prove the indicator continuously and you are contributing evidence toward each control it names. Read it backwards — “this control is covered because an indicator mentions it” — and you have claimed more than the join says, which is the over-claim step 5 exists to train out.

Below is the whole graph, one theme at a time. Open your team’s nearest theme first — the architecture one if you build infrastructure, change management if you own the pipeline. Every id is a page; this walk is how the rest of the site is addressed.

CED — Cybersecurity Education

1 indicators

  • KSI-CED-RAT Reviewing All Training

    The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.

    evidence for: cp-3, ir-2, ps-6, at-2, at-2.2, at-2.3, at-3.5, at-4, ir-2.3, at-3, sr-11.1

CMT — Change Management

4 indicators

CNA — Cloud Native Architecture

8 indicators

  • KSI-CNA-DFP Defining Functionality and Privileges

    The functionality and privileges for infrastructure and services are strictly defined.

    evidence for: cm-2, si-3

  • KSI-CNA-EIS Enforcing Intended State

    States nothing at some classes — an indicator can simply stop, and the schema allows it.

    evidence for: ca-2.1, ca-7.1

  • KSI-CNA-IBP Implementing Best Practices

    The use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance.

    evidence for: ac-17.3, cm-2, pl-10

  • KSI-CNA-MAT Minimizing Attack Surface

    Machine-based information resources are persistently reviewed to ensure they have a minimal attack surface and that lateral movement is minimized if compromised.

    evidence for: ac-17.3, ac-18.1, ac-18.3, ac-20.1, ca-9, sc-7.3, sc-7.4, sc-7.5, sc-7.8, sc-8, sc-10, si-10, si-11, si-16

  • KSI-CNA-OFA Optimizing for Availability

    Machine-based information resources are persistently reviewed to ensure they are appropriately optimized for high availability and rapid recovery.

    reaches no controls

  • KSI-CNA-RNT Restricting Network Traffic

    Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.

    evidence for: ac-17.3, ca-9, cm-7.1, sc-7.5, si-8

  • KSI-CNA-RVP Reviewing Protections

    The effectiveness of protection against denial of service attacks and other unwanted activity for machine-based information resources is persistently reviewed.

    evidence for: sc-5, si-8, si-8.2

  • KSI-CNA-ULN Using Logical Networking

    Logical networking and related capabilities are used and persistently reviewed to enforce traffic flow controls.

    evidence for: ac-12, ac-17.3, ca-9, sc-4, sc-7, sc-7.7, sc-8, sc-10

IAM — Identity and Access Management

6 indicators

INR — Incident Response

3 indicators

MLA — Monitoring, Logging, and Auditing

5 indicators

PIY — Policy and Inventory

5 indicators

  • KSI-PIY-GIV Generating Inventories

    Authoritative sources are used to automatically generate real-time inventories of all information resources when needed.

    evidence for: cm-2.2, cm-7.5, cm-8, cm-8.1, cm-12, cm-12.1, cp-2.8

  • KSI-PIY-RES Reviewing Executive Support

    Executive support for achieving the provider's security goals is persistently reviewed and demonstrated.

    reaches no controls

  • KSI-PIY-RIS Reviewing Investments in Security

    The effectiveness of the provider's investments in achieving security goals is persistently reviewed.

    evidence for: ac-5, ca-2, cp-2.1, cp-4.1, ir-3.2, pm-3, sa-2, sa-3, sr-2.1

  • KSI-PIY-RSD Reviewing Security in the SDLC

    The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.

    evidence for: ac-5, au-3.3, cm-3.4, pl-8, pm-7, sa-3, sa-8, sc-4, sc-18, si-10, si-11, si-16

  • KSI-PIY-RVD Reviewing Vulnerability Disclosures

    The effectiveness of the provider's vulnerability disclosure program is persistently reviewed.

    evidence for: ra-5.11

RPL — Recovery Planning

4 indicators

SCR — Supply Chain Risk

2 indicators

SVC — Service Configuration

8 indicators

Exit check — a colleague says “AC-2 maps to a KSI, so it’s handled.” What did they get backwards?

The direction, and with it the claim. The indicator is evidence towardthe controls it names — proving it contributes; it does not discharge a control by itself, and one control is usually named by several indicators, each covering a different slice. “Handled” is a verdict about the control’s whole requirement, and the join alone never supports it. The two-way instrument for checking any specific edge is /crosswalk.