Class B evidence planour reading: Rev5 impact levelFedRAMP’s three-way sizing of a system — Low, Moderate or High — set by what the data would cost if it leaked. It picks your baseline.
Everything a class B provider owes, grouped by Key Security Indicator (KSI)FedRAMP 20x’s unit of assurance: a question asked of the running system — “is MFA enforced?” — that a machine can answer, grouped into themes. theme, densest theme first. For each item: the AWS and pipeline call that fetches the evidence, the cadenceHow often the rules require a piece of evidence to be refreshed. The clock on an obligation, not the command that satisfies it., and the controlOne numbered security requirement — AC-02, “account management” — from NIST SP 800-53, the catalogue FedRAMP draws its baselines from. it proves. What no API can prove is kept honest, not hidden — the readings below split your baselineThe set of controls one impact level requires. FedRAMP Rev5 publishes three, and which one binds you is the whole question of scope. into what an authored recipeThis product’s unit of collection, and its own coinage: an authored command, plus what one pass of it proves and how often to re-run it. reaches and what stays narrativeNo AWS or pipeline API answers this — it is a document you write., the residueThis product’s word for what no API can produce — the writing a plan still owes. It is kept in view rather than rounded away into a coverage number. you write yourself.
Scopecontrols in the class B baseline
- in scope
- 155
- reached by a KSI
- 95 of 15561% of the baseline
- orphan → narrative
- 60 of 155no indicator reaches these
- with an authored recipe
- 50 of 1550 of them collected unattended
Automationrecipes authored on AWS and pipeline (AWS overlay v3.0.0, pipeline overlay v0.8.0)
- across themes
- 9 / 10
- automatable
- 0 of 64
- partial
- 63 of 64
- narrative
- 1 of 64
One recipe usually proves several controls, so this group never adds up to the one beside it.
Class B vulnerability-response floor
VDR floor7 days
- tightest MUST
- 7 days — VDR-TFR-MVX Persistent Machine Verification and Validation for 20x
A response floor, not a collection interval — why
This is a class-widefloor on responding to a vulnerability, quoted in the dataset’s own units and never converted. It is not a per-check collection interval — the rules author none. Schedule against the MUST; the tightest entry may be a SHOULD.
- automatable
- partial — needs judgement
- narrative — no API proves this
Backlog size: 43 of the 46 Key Security Indicators are in scope for at least one class. The other KSI-CNA-OFA (reaches no control at all), KSI-PIY-RES (reaches no control at all), KSI-SVC-RUD (its 2 control(s) sit outside every Rev5 baseline) can never appear in any plan — listed, not dropped.
IAM — Identity and Access Management
18 recipes · 5 indicatorsSVC — Service Configuration
17 recipes · 5 indicatorsMLA — Monitoring, Logging, and Auditing
9 recipes · 4 indicatorsSCR — Supply Chain Risk
11 recipes · 2 indicatorsCMT — Change Management
10 recipes · 4 indicatorsCNA — Cloud Native Architecture
10 recipes · 7 indicatorsPIY — Policy and Inventory
5 recipes · 4 indicatorsINR — Incident Response
3 recipes · 3 indicatorsRPL — Recovery Planning
2 recipes · 4 indicatorsOn paper: the full plan — every recipe and command, in reading order — prints from its own sheet ▸
This printout is the theme index. The full class plan — every recipe and command — prints from /plan/b/print.
What you can’t automate
60 of the 155 baseline controls are reached by no KSI at all — no 20x telemetry maps to them, so they stay narrative in your Security Decision Record. This residue is the real writing workload; it is listed, never dropped.
the 60 orphan controls ▸