Class D evidence planour reading: Rev5 impact levelFedRAMP’s three-way sizing of a system — Low, Moderate or High — set by what the data would cost if it leaked. It picks your baseline.
Everything a class D provider owes, grouped by Key Security Indicator (KSI)FedRAMP 20x’s unit of assurance: a question asked of the running system — “is MFA enforced?” — that a machine can answer, grouped into themes. theme, densest theme first. For each item: the AWS and pipeline call that fetches the evidence, the cadenceHow often the rules require a piece of evidence to be refreshed. The clock on an obligation, not the command that satisfies it., and the controlOne numbered security requirement — AC-02, “account management” — from NIST SP 800-53, the catalogue FedRAMP draws its baselines from. it proves. What no API can prove is kept honest, not hidden — the readings below split your baselineThe set of controls one impact level requires. FedRAMP Rev5 publishes three, and which one binds you is the whole question of scope. into what an authored recipeThis product’s unit of collection, and its own coinage: an authored command, plus what one pass of it proves and how often to re-run it. reaches and what stays narrativeNo AWS or pipeline API answers this — it is a document you write., the residueThis product’s word for what no API can produce — the writing a plan still owes. It is kept in view rather than rounded away into a coverage number. you write yourself.
Scopecontrols in the class D baseline
- in scope
- 409
- reached by a KSI
- 199 of 40949% of the baseline
- orphan → narrative
- 210 of 409no indicator reaches these
- with an authored recipe
- 94 of 4090 of them collected unattended
Automationrecipes authored on AWS and pipeline (AWS overlay v3.0.0, pipeline overlay v0.8.0)
- across themes
- 9 / 10
- automatable
- 0 of 64
- partial
- 63 of 64
- narrative
- 1 of 64
One recipe usually proves several controls, so this group never adds up to the one beside it.
Class D is still being written
Pendingspecification incomplete
Three places in the rules say so, and all three are read from the dataset rather than from a schedule — so this notice comes down on its own when the text fills in. What IS written for this class is worth building against; what is missing is not a gap in your programme.
- A rule says the specifics are not set yet
“Providers with 20x Class D Certifications MUST significantly supersede the minimum requirements for lower Classes, with specifics to be set during the 20x Phase 4 Pilot.”
- Indicators that state nothing at this class — stated at class C
- A clock with no row at this class — stated at class C
Class D vulnerability-response floor
VDR floor1 month
- tightest MUST
- 1 month — VDR-TFR-MVF Persistent Machine Verification and Validation for Rev5
- tightest overall
- 1 day — VDR-TFR-PSD SHOULD, so it does not bind
A response floor, not a collection interval — why
This is a class-widefloor on responding to a vulnerability, quoted in the dataset’s own units and never converted. It is not a per-check collection interval — the rules author none. Schedule against the MUST; the tightest entry may be a SHOULD.
- automatable
- partial — needs judgement
- narrative — no API proves this
Backlog size: 43 of the 46 Key Security Indicators are in scope for at least one class. The other KSI-CNA-OFA (reaches no control at all), KSI-PIY-RES (reaches no control at all), KSI-SVC-RUD (its 2 control(s) sit outside every Rev5 baseline) can never appear in any plan — listed, not dropped.
IAM — Identity and Access Management
18 recipes · 6 indicatorsSVC — Service Configuration
17 recipes · 7 indicatorsMLA — Monitoring, Logging, and Auditing
9 recipes · 5 indicatorsCNA — Cloud Native Architecture
10 recipes · 7 indicatorsPIY — Policy and Inventory
5 recipes · 4 indicatorsRPL — Recovery Planning
2 recipes · 4 indicatorsSCR — Supply Chain Risk
11 recipes · 2 indicatorsCMT — Change Management
10 recipes · 4 indicatorsINR — Incident Response
3 recipes · 3 indicatorsOn paper: the full plan — every recipe and command, in reading order — prints from its own sheet ▸
This printout is the theme index. The full class plan — every recipe and command — prints from /plan/d/print.
What you can’t automate
210 of the 409 baseline controls are reached by no KSI at all — no 20x telemetry maps to them, so they stay narrative in your Security Decision Record. This residue is the real writing workload; it is listed, never dropped.
the 210 orphan controls ▸