Monitoring, Logging, and Auditing¶
Authorizing Log Access¶
KSI-MLA-ALA
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Optional: A least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity.
A least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity.
Related SP 800-53 Controls: SI-11
Terms: Persistently
Evaluating Configurations¶
KSI-MLA-EVC
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The configuration of machine-based information resources, especially infrastructure as code, is persistently evaluated and tested.
Related SP 800-53 Controls: CA-07, CM-02, CM-06, SI-07 (07)
Terms: Information Resource, Machine-Based (Information Resources), Persistently
Logging Event Types¶
KSI-MLA-LET
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
A list of information resources and event types that will be logged, monitored, and audited is maintained and persistently reviewed to ensure these activities occur.
Related SP 800-53 Controls: AC-02 (04), AC-06 (09), AC-17 (01), AC-20 (01), AU-02, AU-07 (01), AU-12, SI-04 (04), SI-04 (05), SI-07 (07)
Terms: Information Resource, Persistently
Operating SIEM Capability¶
KSI-MLA-OSM
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
A Security Information and Event Management (SIEM) or similar system(s) is used and persistently reviewed for centralized, tamper-resistant logging of events, activities, and changes.
Related SP 800-53 Controls: AC-17 (01), AC-20 (01), AU-02, AU-03, AU-03 (01), AU-04, AU-05, AU-06 (01), AU-06 (03), AU-07, AU-07 (01), AU-08, AU-09, AU-11, IR-04 (01), SI-04 (02), SI-04 (04), SI-07 (07)
Terms: Persistently
Reviewing Logs¶
KSI-MLA-RVL
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Logs are persistently reviewed and audited.
Related SP 800-53 Controls: AC-02 (04), AC-06 (09), AU-02, AU-06, AU-06 (01), SI-04, SI-04 (04)
Terms: Persistently