Key Security Indicators¶
Cybersecurity Education¶
Reviewing All Training¶
KSI-CED-RAT
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.
Related SP 800-53 Controls: CP-03, IR-02, PS-06, AT-02, AT-02 (02), AT-02 (03), AT-03 (05), AT-04, IR-02 (03), AT-03, SR-11 (01)
Terms: Incident, Persistently, Vulnerability Response
Change Management¶
Logging Changes¶
KSI-CMT-LMC
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Modifications to the cloud service offering are logged and monitored.
Related SP 800-53 Controls: AU-02, CM-03, CM-03 (02), CM-04 (02), CM-06, CM-08 (03), MA-02
Terms: Cloud Service Offering
Redeploying vs Modifying¶
KSI-CMT-RMV
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Changes to machine-based information resources are executed through the redeployment of version controlled resources rather than direct modification wherever reasonable.
Related SP 800-53 Controls: CM-02, CM-03, CM-05, CM-06, CM-07, CM-08 (01), SI-03
Terms: Information Resource, Machine-Based (Information Resources)
Reviewing Change Procedures¶
KSI-CMT-RVP
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The effectiveness of documented change management procedures is persistently reviewed.
Related SP 800-53 Controls: CM-03, CM-03 (02), CM-03 (04), CM-05, CM-07 (01), CM-09
Terms: Persistently
Validating Throughout Deployment¶
KSI-CMT-VTD
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Persistent testing and validation of changes throughout deployment is automated.
Related SP 800-53 Controls: CM-03, CM-03 (02), CM-04 (02), SI-02
Terms: Persistently, Validation
Cloud Native Architecture¶
Defining Functionality and Privileges¶
KSI-CNA-DFP
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The functionality and privileges for infrastructure and services are strictly defined.
Enforcing Intended State¶
KSI-CNA-EIS
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Optional: Automated services are used to persistently assess the security of all machine-based information resources and automatically enforce their intended operational state.
Automated services are used to persistently assess the security of all machine-based information resources and automatically enforce their intended operational state.
Related SP 800-53 Controls: CA-02 (01), CA-07 (01)
Terms: Information Resource, Machine-Based (Information Resources), Persistently
Implementing Best Practices¶
KSI-CNA-IBP
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance.
Related SP 800-53 Controls: AC-17 (03), CM-02, PL-10
Terms: Information Resource, Machine-Based (Information Resources), Persistently
Minimizing Attack Surface¶
KSI-CNA-MAT
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Machine-based information resources are persistently reviewed to ensure they have a minimal attack surface and that lateral movement is minimized if compromised.
Related SP 800-53 Controls: AC-17 (03), AC-18 (01), AC-18 (03), AC-20 (01), CA-09, SC-07 (03), SC-07 (04), SC-07 (05), SC-07 (08), SC-08, SC-10, SI-10, SI-11, SI-16
Terms: Information Resource, Machine-Based (Information Resources), Persistently
Optimizing for Availability¶
KSI-CNA-OFA
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Machine-based information resources are persistently reviewed to ensure they are appropriately optimized for high availability and rapid recovery.
Terms: Information Resource, Machine-Based (Information Resources), Persistently
Restricting Network Traffic¶
KSI-CNA-RNT
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.
Related SP 800-53 Controls: AC-17 (03), CA-09, CM-07 (01), SC-07 (05), SI-08
Terms: Information Resource, Machine-Based (Information Resources), Persistently
Reviewing Protections¶
KSI-CNA-RVP
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The effectiveness of protection against denial of service attacks and other unwanted activity for machine-based information resources is persistently reviewed.
Related SP 800-53 Controls: SC-05, SI-08, SI-08 (02)
Terms: Information Resource, Machine-Based (Information Resources), Persistently
Using Logical Networking¶
KSI-CNA-ULN
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Logical networking and related capabilities are used and persistently reviewed to enforce traffic flow controls.
Related SP 800-53 Controls: AC-12, AC-17 (03), CA-09, SC-04, SC-07, SC-07 (07), SC-08, SC-10
Terms: Persistently
Identity and Access Management¶
Automating Account Management¶
KSI-IAM-AAM
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.
Related SP 800-53 Controls: AC-02 (02), AC-02 (03), AC-02 (13), AC-06 (07), IA-04 (04), IA-12, IA-12 (02), IA-12 (03), IA-12 (05)
Adopting Passwordless Methods¶
KSI-IAM-APM
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.
Related SP 800-53 Controls: AC-03, IA-05 (01), IA-05 (02), IA-05 (06), IA-06, AC-02, IA-02, IA-02 (01), IA-02 (02), IA-02 (08), IA-05, IA-08, SC-23
Ensuring Least Privilege¶
KSI-IAM-ELP
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Identity and access management measures are used and persistently reviewed to ensure each user or device can only access the resources they need.
Related SP 800-53 Controls: AC-02 (05), AC-02 (06), AC-03, AC-04, AC-06, AC-12, AC-14, AC-17, AC-17 (01), AC-17 (02), AC-17 (03), AC-20, AC-20 (01), CM-02 (07), CM-09, IA-02, IA-03, IA-04, IA-04 (04), IA-05 (02), IA-05 (06), IA-11, PS-02, PS-03, PS-04, PS-05, PS-06, SC-04, SC-20, SC-21, SC-22, SC-23, SC-39, SI-03
Terms: Persistently
Authorizing Just-in-Time¶
KSI-IAM-JIT
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
A least-privileged, role and attribute-based, and just-in-time security authorization model is used and persistently reviewed for all user and non-user accounts and services.
Related SP 800-53 Controls: AC-02, AC-02 (01), AC-02 (02), AC-02 (03), AC-02 (04), AC-02 (06), AC-03, AC-04, AC-05, AC-06, AC-06 (01), AC-06 (02), AC-06 (05), AC-06 (07), AC-06 (09), AC-06 (10), AC-07, AC-20 (01), AC-17, AU-09 (04), CM-05, CM-07, CM-07 (02), CM-07 (05), CM-09, IA-04, IA-04 (04), IA-07, PS-02, PS-03, PS-04, PS-05, PS-06, PS-09, RA-05 (05), SC-02, SC-23, SC-39
Terms: Persistently
Securing Non-User Authentication¶
KSI-IAM-SNU
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Appropriately secure authentication methods are used and persistently reviewed for non-user accounts and services.
Related SP 800-53 Controls: AC-02, AC-02 (02), AC-04, AC-06 (05), IA-03, IA-05 (02), RA-05 (05)
Terms: Persistently
Responding to Suspicious Activity¶
KSI-IAM-SUS
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Accounts with privileged access are disabled or otherwise secured in response to suspicious activity.
Related SP 800-53 Controls: AC-02, AC-02 (01), AC-02 (03), AC-02 (13), AC-07, PS-04, PS-08
Terms: Vulnerability Response
Incident Response¶
Generating After Action Reports¶
KSI-INR-AAR
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Incident after action reports are generated and lessons learned are persistently incorporated.
Related SP 800-53 Controls: IR-03, IR-04, IR-04 (01), IR-08
Terms: Incident, Persistently
Reviewing Incident Response Procedures¶
KSI-INR-RIR
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The effectiveness of documented incident response procedures is persistently reviewed.
Related SP 800-53 Controls: IR-04, IR-04 (01), IR-06, IR-06 (01), IR-06 (03), IR-07, IR-07 (01), IR-08, IR-08 (01), SI-04 (05)
Terms: Incident, Persistently, Vulnerability Response
Reviewing Past Incidents¶
KSI-INR-RPI
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Past incidents are persistently reviewed for patterns or vulnerabilities that were not previously apparent or identified.
Related SP 800-53 Controls: IR-03, IR-04, IR-04 (01), IR-05, IR-08
Terms: Incident, Persistently, Vulnerability
Monitoring, Logging, and Auditing¶
Authorizing Log Access¶
KSI-MLA-ALA
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Optional: A least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity.
A least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity.
Related SP 800-53 Controls: SI-11
Terms: Persistently
Evaluating Configurations¶
KSI-MLA-EVC
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The configuration of machine-based information resources, especially infrastructure as code, is persistently evaluated and tested.
Related SP 800-53 Controls: CA-07, CM-02, CM-06, SI-07 (07)
Terms: Information Resource, Machine-Based (Information Resources), Persistently
Logging Event Types¶
KSI-MLA-LET
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
A list of information resources and event types that will be logged, monitored, and audited is maintained and persistently reviewed to ensure these activities occur.
Related SP 800-53 Controls: AC-02 (04), AC-06 (09), AC-17 (01), AC-20 (01), AU-02, AU-07 (01), AU-12, SI-04 (04), SI-04 (05), SI-07 (07)
Terms: Information Resource, Persistently
Operating SIEM Capability¶
KSI-MLA-OSM
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
A Security Information and Event Management (SIEM) or similar system(s) is used and persistently reviewed for centralized, tamper-resistant logging of events, activities, and changes.
Related SP 800-53 Controls: AC-17 (01), AC-20 (01), AU-02, AU-03, AU-03 (01), AU-04, AU-05, AU-06 (01), AU-06 (03), AU-07, AU-07 (01), AU-08, AU-09, AU-11, IR-04 (01), SI-04 (02), SI-04 (04), SI-07 (07)
Terms: Persistently
Reviewing Logs¶
KSI-MLA-RVL
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Logs are persistently reviewed and audited.
Related SP 800-53 Controls: AC-02 (04), AC-06 (09), AU-02, AU-06, AU-06 (01), SI-04, SI-04 (04)
Terms: Persistently
Policy and Inventory¶
Generating Inventories¶
KSI-PIY-GIV
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Authoritative sources are used to automatically generate real-time inventories of all information resources when needed.
Related SP 800-53 Controls: CM-02 (02), CM-07 (05), CM-08, CM-08 (01), CM-12, CM-12 (01), CP-02 (08)
Terms: Information Resource
Reviewing Executive Support¶
KSI-PIY-RES
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Executive support for achieving the provider's security goals is persistently reviewed and demonstrated.
Terms: Persistently
Reviewing Investments in Security¶
KSI-PIY-RIS
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The effectiveness of the provider's investments in achieving security goals is persistently reviewed.
Related SP 800-53 Controls: AC-05, CA-02, CP-02 (01), CP-04 (01), IR-03 (02), PM-03, SA-02, SA-03, SR-02 (01)
Terms: Persistently
Reviewing Security in the SDLC¶
KSI-PIY-RSD
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.
Related SP 800-53 Controls: AC-05, AU-03 (03), CM-03 (04), PL-08, PM-07, SA-03, SA-08, SC-04, SC-18, SI-10, SI-11, SI-16
Terms: Persistently
Reviewing Vulnerability Disclosures¶
KSI-PIY-RVD
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The effectiveness of the provider's vulnerability disclosure program is persistently reviewed.
Related SP 800-53 Controls: RA-05 (11)
Terms: Persistently, Vulnerability
Recovery Planning¶
Aligning Backups with Objectives¶
KSI-RPL-ABO
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The alignment of machine-based information resource backups with defined recovery objectives is persistently reviewed.
Related SP 800-53 Controls: CM-02 (03), CP-06, CP-09, CP-10, CP-10 (02), SI-12
Terms: Information Resource, Machine-Based (Information Resources), Persistently
Aligning Recovery Plan¶
KSI-RPL-ARP
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The alignment of recovery plans with defined recovery objectives is persistently reviewed.
Related SP 800-53 Controls: CP-02, CP-02 (01), CP-02 (03), CP-04 (01), CP-06, CP-06 (01), CP-06 (03), CP-07, CP-07 (01), CP-07 (02), CP-07 (03), CP-08, CP-08 (01), CP-08 (02), CP-10, CP-10 (02)
Terms: Persistently
Reviewing Recovery Objectives¶
KSI-RPL-RRO
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The desired Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and persistently reviewed for alignment with the provider's business needs and capabilities.
Related SP 800-53 Controls: CP-02 (03), CP-10
Terms: Persistently
Testing Recovery Capabilities¶
KSI-RPL-TRC
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The capability to recover from incidents and contingencies aligned with defined recovery objectives is persistently tested.
Related SP 800-53 Controls: CP-02 (01), CP-02 (03), CP-04, CP-04 (01), CP-06, CP-06 (01), CP-09 (01), CP-10, IR-03, IR-03 (02)
Terms: Incident, Persistently
Supply Chain Risk¶
Mitigating Supply Chain Risk¶
KSI-SCR-MIT
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Persistently identify, review, and mitigate potential supply chain risks.
Related SP 800-53 Controls: AC-20, RA-03 (01), SA-09, SA-10, SA-11, SA-15 (03), SA-22, SI-07 (01), SR-05, SR-06, CA-07 (04), SC-18
Terms: Persistently
Monitoring Supply Chain Risk¶
KSI-SCR-MON
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.
Related SP 800-53 Controls: AC-20, CA-03, IR-06 (03), PS-07, RA-05, SA-09, SI-05, SR-05, SR-06, SR-08
Terms: Information Resource, Vulnerability
Service Configuration¶
Automating Configuration Management¶
KSI-SVC-ACM
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
The configuration of machine-based information resources is managed using automation and persistently reviewed for drift.
Related SP 800-53 Controls: AC-02 (04), CM-02, CM-02 (02), CM-02 (03), CM-06, CM-07 (01), PL-09, PL-10, SA-05, SI-05, SR-10
Terms: Drift, Information Resource, Machine-Based (Information Resources), Persistently
Automating Secret Management¶
KSI-SVC-ASM
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Management, protection, and regular rotation of digital keys, certificates, and other secrets is automated and persistently reviewed.
Related SP 800-53 Controls: AC-17 (02), IA-05 (02), IA-05 (06), SC-12, SC-17
Terms: Persistently, Regularly
Evaluating and Improving Security¶
KSI-SVC-EIS
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Information resources are persistently evaluated for opportunities to improve security and those improvements are persistently made.
Related SP 800-53 Controls: CM-07 (01), CM-12 (01), MA-02, PL-08, SC-07, SC-39, SI-02 (02), SI-04, SR-10
Terms: Information Resource, Persistently
Preventing Residual Risk¶
KSI-SVC-PRR
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Optional: Plans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data.
Plans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data.
Related SP 800-53 Controls: SC-04
Terms: Federal Customer Data, Information Resource, Likely, Persistently
Removing Unwanted Data¶
KSI-SVC-RUD
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Optional: Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage.
Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage.
Related SP 800-53 Controls: SI-12 (03), SI-18 (04)
Terms: Federal Customer Data, Promptly
Securing Information¶
KSI-SVC-SIN
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Information is encrypted or otherwise secured from unwanted access or modification.
Related SP 800-53 Controls: AC-01, AC-17 (02), CP-09 (08), SC-08, SC-08 (01), SC-13, SC-20, SC-21, SC-22, SC-23, SC-28, SC-28 (01)
Validating Communications¶
KSI-SVC-VCM
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Optional: The authenticity and integrity of communications between machine-based information resources is persistently validated using automation.
The authenticity and integrity of communications between machine-based information resources is persistently validated using automation.
Related SP 800-53 Controls: SC-23, SI-07 (01)
Terms: Information Resource, Machine-Based (Information Resources), Persistently, Validation
Validating Resource Integrity¶
KSI-SVC-VRI
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Use cryptographic methods to validate the integrity of machine-based information resources.
Related SP 800-53 Controls: CM-02 (02), CM-08 (03), SC-13, SC-23, SI-07, SI-07 (01), SR-10
Terms: Information Resource, Machine-Based (Information Resources), Validation