Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Class B evidence planour reading: Rev5 impact levelFedRAMP’s three-way sizing of a system — Low, Moderate or High — set by what the data would cost if it leaked. It picks your baseline.

Everything a class B provider owes, grouped by Key Security Indicator (KSI)FedRAMP 20x’s unit of assurance: a question asked of the running system — “is MFA enforced?” — that a machine can answer, grouped into themes. theme, densest theme first. For each item: the AWS and pipeline call that fetches the evidence, the cadenceHow often the rules require a piece of evidence to be refreshed. The clock on an obligation, not the command that satisfies it., and the controlOne numbered security requirement — AC-02, “account management” — from NIST SP 800-53, the catalogue FedRAMP draws its baselines from. it proves. What no API can prove is kept honest, not hidden — the readings below split your baselineThe set of controls one impact level requires. FedRAMP Rev5 publishes three, and which one binds you is the whole question of scope. into what an authored recipeThis product’s unit of collection, and its own coinage: an authored command, plus what one pass of it proves and how often to re-run it. reaches and what stays narrativeNo AWS or pipeline API answers this — it is a document you write., the residueThis product’s word for what no API can produce — the writing a plan still owes. It is kept in view rather than rounded away into a coverage number. you write yourself.

Scopecontrols in the class B baseline

in scope
155
reached by a KSI
95 of 15561% of the baseline
orphan → narrative
60 of 155no indicator reaches these
with an authored recipe
50 of 1550 of them collected unattended

Automationrecipes authored on AWS and pipeline (AWS overlay v3.0.0, pipeline overlay v0.8.0)

across themes
9 / 10
automatable
0 of 64
partial
63 of 64
narrative
1 of 64

One recipe usually proves several controls, so this group never adds up to the one beside it.

Class B vulnerability-response floor

VDR floor7 days

tightest MUST
7 days VDR-TFR-MVX Persistent Machine Verification and Validation for 20x
A response floor, not a collection interval — why

This is a class-widefloor on responding to a vulnerability, quoted in the dataset’s own units and never converted. It is not a per-check collection interval — the rules author none. Schedule against the MUST; the tightest entry may be a SHOULD.

  • automatable
  • partial — needs judgement
  • narrative — no API proves this

Backlog size: 43 of the 46 Key Security Indicators are in scope for at least one class. The other KSI-CNA-OFA (reaches no control at all), KSI-PIY-RES (reaches no control at all), KSI-SVC-RUD (its 2 control(s) sit outside every Rev5 baseline) can never appear in any plan — listed, not dropped.

IAMIdentity and Access Management

18 recipes · 5 indicators
control reach13 of 31 controls
partial17partialnarrative1narrative
open the build sprint

SVCService Configuration

17 recipes · 5 indicators
control reach13 of 21 controls
partial17partial
open the build sprint
control reach12 of 13 controls
partial9partial
open the build sprint

SCRSupply Chain Risk

11 recipes · 2 indicators
control reach7 of 11 controls
partial11partial
open the build sprint

CMTChange Management

10 recipes · 4 indicators
control reach8 of 8 controls
partial10partial
open the build sprint

CNACloud Native Architecture

10 recipes · 7 indicators
control reach8 of 8 controls
partial10partial
open the build sprint

PIYPolicy and Inventory

5 recipes · 4 indicators
control reach2 of 8 controls
partial5partial
open the build sprint

INRIncident Response

3 recipes · 3 indicators
control reach5 of 5 controls
partial3partial
open the build sprint

RPLRecovery Planning

2 recipes · 4 indicators
control reach2 of 5 controls
partial2partial
open the build sprint

On paper: the full plan — every recipe and command, in reading order — prints from its own sheet ▸

1 theme have no authored recipes yet — CED (1 indicator still in scope)

The overlay is written theme by theme, densest first. These indicators and their controls are in scope regardless; until a recipe exists they are collected by hand.

  • CEDCybersecurity Education1 indicators · 8 controls in scope

What you can’t automate

60 of the 155 baseline controls are reached by no KSI at all — no 20x telemetry maps to them, so they stay narrative in your Security Decision Record. This residue is the real writing workload; it is listed, never dropped.

the 60 orphan controls ▸
No accounts — your progress ticks never leave this browser.