Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Tools & platforms

You already run some of these. This is what each one proves — every tool the authored recipeThis product’s unit of collection, and its own coinage: an authored command, plus what one pass of it proves and how often to re-run it. call, on AWS and pipeline, which are this product’s evidence planeA kind of question, not a vendor. The AWS plane asks a running account what it is doing; the pipeline plane asks the code and the build., with the controlOne numbered security requirement — AC-02, “account management” — from NIST SP 800-53, the catalogue FedRAMP draws its baselines from. its output is evidence for. Start from the console you have open rather than from a baselineThe set of controls one impact level requires. FedRAMP Rev5 publishes three, and which one binds you is the whole question of scope. you have not read.

Tools with a pagetools the authored recipes call

called by a recipe
59
top-level, before capabilities
52

A tool is counted once, under its canonical name. Two overlays spelled five services two ways each, and a page keyed on the raw string would have reported both spellings as separate tools.

Recipesauthored recipes across every plane

reaching at least one tool
64
in the corpus
64

A recipe naming a service and one of its capabilities is one recipe, counted once against each and once — not twice — against the parent.

What each one proves

densest first — the corpus converged hard on a few evaluators, and an alphabetical list would bury that

Named, and not authored yet

no page, because there is nothing on it

The automation register names these as candidates for controls nobody has written a recipe for. If you run one, the honest answer today is that this product has nothing authored for it — which is a better answer than a page implying otherwise.

  • AWS CloudHSM
  • AWS Private CA
  • AWS Secrets Manager
  • Amazon S3 Block Public Access
  • AWS Elastic Disaster Recovery
  • AWS Resilience Hub
  • AWS Firewall Manager
  • AWS CloudFormation
  • AWS CodePipeline

Tool names are canonical, from data/overlays/aws-services.json (v1.1.0) and data/overlays/pipeline-tools.json (v0.7.0). Neither is a catalogue of its vendor: an entry is added by the batch that first names the tool.