diff --git a/fedramp-consolidated-rules.json b/fedramp-consolidated-rules.json index 27de6b6..af4e0e2 100644 --- a/fedramp-consolidated-rules.json +++ b/fedramp-consolidated-rules.json @@ -1387,6 +1387,7 @@ "artifacts": { "all": ["Email address to receive messages from FedRAMP"] }, + "controls": ["si-5"], "terms": ["FedRAMP Security Inbox"], "updated": [ { @@ -1788,6 +1789,7 @@ "statement": "Agencies MUST review the Secure Configuration Guides supplied by Providers and configure relevant security settings.", "force": "MUST", "affects": ["Agencies"], + "controls": ["cm-10", "cm-5", "cm-6", "ia-11"], "terms": [], "updated": [ { @@ -2092,6 +2094,7 @@ }, "timeframe_type": "months", "timeframe_num": 3, + "controls": ["ca-7"], "terms": [ "Accepted Vulnerability", "All Necessary Parties", @@ -2281,6 +2284,7 @@ } }, "affects": ["Providers"], + "controls": ["ca-7"], "terms": [ "All Necessary Parties", "Ongoing Certification", @@ -2362,6 +2366,7 @@ "statement": "Providers SHOULD supply additional information in Quarterly Reviews that the provider determines is of interest, use, or otherwise relevant to agencies.", "force": "SHOULD", "affects": ["Providers"], + "controls": ["ca-7"], "terms": ["Quarterly Review"], "updated": [ { @@ -3140,6 +3145,7 @@ "List of cryptographic modules including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules." ] }, + "controls": ["au-9.3", "cm-3.6", "ia-7", "sc-28.1", "sc-8.1"], "terms": ["Federal Customer Data", "Validation"], "updated": [ { @@ -3190,6 +3196,7 @@ }, "note": "Cryptographic modules include specific algorithms by definition; if an update stream of a cryptographic module adds new algorithms that were not previously validated then those algorithms can not be considered within the scope of update stream usage under these rules as they are new algorithms within the module that have never been validated.", "affects": ["Providers"], + "controls": ["ac-18", "au-9.3", "ia-7", "sc-28.1", "sc-8.1"], "terms": ["Federal Customer Data", "Validation"], "updated": [ { @@ -3396,6 +3403,7 @@ }, "related": ["IVV-IAS-OSA"], "affects": ["Providers"], + "controls": ["ca-2", "ca-2.1", "ca-2.2", "ca-7.1"], "terms": [ "Certification Package", "FedRAMP Independent Assessment" @@ -4208,6 +4216,7 @@ } }, "affects": ["Providers"], + "controls": ["cm-2.2", "si-6"], "terms": ["Persistently", "Validation", "Verification"], "updated": [ { @@ -4268,6 +4277,7 @@ }, "note": "Different rules will be easy to automate for different providers, depending on the implementation, so FedRAMP generally leaves this implementation up to providers based on what makes the most sense for their own business and approach.", "affects": ["Providers"], + "controls": ["si-6"], "terms": [ "Persistently", "Security Decision Record (SDR)", @@ -5518,6 +5528,7 @@ "An incident log showing an example of one or more incidents being evaluated including the reason for the determination. The log can be from real incidents, simulated incidents, or a combination of sources." ] }, + "controls": ["au-5.2", "ir-4.11"], "terms": [ "FedRAMP Reportable Incident", "Federal Customer Data", @@ -5809,6 +5820,7 @@ "name": "Provider's Trust Center or USDA Connect" } ], + "controls": ["au-5.2", "ir-5"], "terms": [ "All Affected Parties", "FedRAMP Reportable Incident", @@ -6064,6 +6076,7 @@ "name": "Provider's Trust Center or USDA Connect" } ], + "controls": ["ir-5"], "terms": [ "All Affected Parties", "FedRAMP Reportable Incident", @@ -6295,6 +6308,7 @@ "name": "Provider's Trust Center or USDA Connect" } ], + "controls": ["ir-5"], "terms": [ "All Affected Parties", "Final Incident Report (FIR)", @@ -6493,6 +6507,7 @@ "FedRAMP Recognized independent assessment services are listed on the FedRAMP Marketplace." ], "affects": ["Providers"], + "controls": ["ca-2", "ca-2.1", "ca-2.2", "ca-7.1", "ca-7.4"], "terms": [ "Certification Class", "FedRAMP Independent Assessment", @@ -6651,6 +6666,7 @@ "note": "This requires reviewing the actual measures themselves at a technical level, such as reviewing underlying code as appropriate; don't simply review documentation or screenshots.", "force": "MUST", "affects": ["Assessors"], + "controls": [], "terms": ["FedRAMP Practices", "Validation"], "updated": [ { @@ -7177,6 +7193,7 @@ "The code for the automated process used to generate the machine readable output." ] }, + "controls": ["cm-8.4", "ra-3", "si-4.19"], "terms": [ "Certification Package", "Cloud Service Offering", @@ -7205,6 +7222,7 @@ "The code for the automated process used to generate the machine readable output." ] }, + "controls": ["ac-4", "cm-12", "cm-12.1", "ra-3", "si-4.19"], "terms": [ "Cloud Service Offering", "Handle", @@ -7242,6 +7260,7 @@ "name": "FedRAMP Certification Package Overview (FRC-CSO-PKG)", "url": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json" }, + "controls": ["ra-3"], "terms": [ "Cloud Service Offering", "Federal Customer Data", @@ -8038,6 +8057,7 @@ "name": "FedRAMP Certification Package Overview (FRC-CSO-PKG)", "url": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json" }, + "controls": ["cm-7"], "terms": [ "Cloud Service Offering", "Privileged Account", @@ -8349,6 +8369,7 @@ "name": "FedRAMP Significant Change Notification (SCN-CSO-INF)", "url": "https://fedramp.gov/schemas/fedramp-significant-change-notifications-schema-2026-06-24.json" }, + "controls": ["cm-4"], "terms": [ "Adaptive Change", "Certification Class", @@ -8505,6 +8526,7 @@ "note": "Procedures for emergency changes should be documented in the FedRAMP Certification Package.", "force": "MAY", "affects": ["Providers"], + "controls": ["ir-4.2"], "terms": [ "All Necessary Parties", "Certification Package", @@ -9121,6 +9143,24 @@ ], "force": "MUST", "affects": ["Providers"], + "controls": [ + "au-5.2", + "au-6", + "ca-8", + "ca-8.1", + "ca-8.2", + "ra-5", + "ra-5.2", + "ra-5.3", + "ra-5.4", + "si-2", + "si-3", + "si-4.1", + "si-4.12", + "si-4.18", + "si-4.22", + "si-5.1" + ], "terms": [ "Cloud Service Offering", "FedRAMP Practices", @@ -9149,6 +9189,14 @@ ], "force": "MUST", "affects": ["Providers"], + "controls": [ + "au-5.2", + "ir-4.11", + "ir-9.3", + "ra-7", + "si-2", + "si-3" + ], "terms": [ "Cloud Service Offering", "Fully Mitigated Vulnerability", @@ -9172,6 +9220,7 @@ "statement": "Providers MUST treat problems or failures with their vulnerability detection and response processes as vulnerabilities.", "force": "MUST", "affects": ["Providers"], + "controls": ["au-5.2", "si-4", "si-4.1", "si-7.7"], "terms": [ "Vulnerability", "Vulnerability Detection", @@ -9207,6 +9256,7 @@ "statement": "Providers SHOULD use automated services to improve and streamline vulnerability detection and response.", "force": "SHOULD", "affects": ["Providers"], + "controls": ["ra-5", "si-2.2", "si-3", "si-4.2", "si-4.5"], "terms": [ "Vulnerability", "Vulnerability Detection", @@ -9224,6 +9274,7 @@ "statement": "Providers SHOULD automatically perform vulnerability detection on representative samples of new or significantly changed information resources.", "force": "SHOULD", "affects": ["Providers"], + "controls": ["ra-5"], "terms": [ "Information Resource", "Vulnerability", @@ -9241,6 +9292,7 @@ "statement": "Providers SHOULD NOT weaken the security of information resources to facilitate vulnerability scanning, detection, or assessment activities.", "force": "SHOULD NOT", "affects": ["Providers"], + "controls": ["ra-5.5", "si-2"], "terms": [ "Information Resource", "Vulnerability", @@ -9258,6 +9310,7 @@ "statement": "Providers SHOULD NOT deploy or otherwise activate new machine-based information resources with Known Exploited Vulnerabilities.", "force": "SHOULD NOT", "affects": ["Providers"], + "controls": ["ra-5", "si-5"], "terms": [ "Information Resource", "Known Exploited Vulnerability (KEV)", @@ -9276,6 +9329,7 @@ "statement": "Providers MAY sample effectively identical information resources, especially machine-based information resources, when performing vulnerability detection UNLESS doing so would decrease the efficiency or effectiveness of vulnerability detection.", "force": "MAY", "affects": ["Providers"], + "controls": ["ra-5.3", "ra-5.5"], "terms": [ "Information Resource", "Machine-Based (Information Resources)", @@ -9340,6 +9394,7 @@ } }, "affects": ["Providers"], + "controls": ["si-4.22", "si-7", "si-7.1"], "terms": [ "Drift", "Information Resource", @@ -9705,6 +9760,7 @@ }, "related": ["VER-EVA-EPA"], "affects": ["Providers"], + "controls": ["si-2.3"], "terms": [ "Fully Mitigated Vulnerability", "Likely", @@ -10083,6 +10139,7 @@ ], "force": "MUST", "affects": ["Providers"], + "controls": ["ra-3"], "terms": [ "Cloud Service Offering", "Debilitating Customer Effect", @@ -10170,6 +10227,7 @@ ], "force": "SHOULD", "affects": ["Providers"], + "controls": ["ra-9"], "terms": [ "Cloud Service Offering", "Fully Mitigated Vulnerability", @@ -10195,6 +10253,7 @@ "name": "FedRAMP Vulnerability Detail Report (VER-RPT-VDT)", "url": "https://fedramp.gov/schemas/fedramp-vulnerability-detail-report-schema-2026-06-24.json" }, + "controls": ["si-7.2"], "terms": [ "All Necessary Parties", "Certification Data", @@ -10239,6 +10298,7 @@ "name": "FedRAMP Vulnerability Detail Report (VER-RPT-VDT)", "url": "https://fedramp.gov/schemas/fedramp-vulnerability-detail-report-schema-2026-06-24.json" }, + "controls": ["si-2.3"], "terms": [ "Accepted Vulnerability", "Cloud Service Offering", @@ -10591,16 +10651,24 @@ "name": "Reviewing All Training", "statement": "The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.", "controls": [ - "cp-3", - "ir-2", - "ps-6", "at-2", "at-2.2", "at-2.3", + "at-3", "at-3.5", "at-4", + "cm-11", + "cp-3", + "cp-3.1", + "ir-2", + "ir-2.1", + "ir-2.2", "ir-2.3", - "at-3", + "ir-9.2", + "ir-9.4", + "pl-4", + "pl-4.1", + "ps-6", "sr-11.1" ], "updated": [ @@ -10625,12 +10693,14 @@ "statement": "Modifications to the cloud service offering are logged and monitored.", "controls": [ "au-2", + "ca-7.4", "cm-3", + "cm-3.1", "cm-3.2", + "cm-3.6", "cm-4.2", "cm-6", - "cm-8.3", - "ma-2" + "cm-8.3" ], "updated": [ { @@ -10678,7 +10748,7 @@ "KSI-CMT-VTD": { "name": "Validating Throughout Deployment", "statement": "Persistent testing and validation of changes throughout deployment is automated.", - "controls": ["cm-3", "cm-3.2", "cm-4.2", "si-2"], + "controls": ["cm-3", "cm-3.2", "cm-4.2", "cm-6.2", "ir-9.4", "si-2"], "updated": [ { "date": "2026-06-24", @@ -10699,7 +10769,7 @@ "KSI-CNA-DFP": { "name": "Defining Functionality and Privileges", "statement": "The functionality and privileges for infrastructure and services are strictly defined.", - "controls": ["cm-2", "si-3"], + "controls": ["cm-2", "cm-8.4", "cp-10.4", "ir-9.4", "si-3"], "updated": [ { "date": "2026-06-24", @@ -10709,7 +10779,20 @@ }, "KSI-CNA-EIS": { "name": "Enforcing Intended State", - "controls": ["ca-2.1", "ca-7.1"], + "controls": [ + "ca-2.1", + "cm-11", + "cm-6.2", + "cp-10.4", + "ir-9.4", + "sc-24", + "sc-7.18", + "si-4.22", + "si-7", + "si-7.1", + "si-7.5", + "si-7.7" + ], "updated": [ { "date": "2026-06-24", @@ -10733,7 +10816,7 @@ "KSI-CNA-IBP": { "name": "Implementing Best Practices", "statement": "The use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance.", - "controls": ["ac-17.3", "cm-2", "pl-10"], + "controls": ["ac-17.3", "cm-2", "pl-10", "sc-7.18"], "updated": [ { "date": "2026-06-24", @@ -10755,12 +10838,13 @@ "ac-18.3", "ac-20.1", "ca-9", + "sc-10", + "sc-7.18", "sc-7.3", "sc-7.4", "sc-7.5", "sc-7.8", "sc-8", - "sc-10", "si-10", "si-11", "si-16" @@ -10780,7 +10864,7 @@ "KSI-CNA-OFA": { "name": "Optimizing for Availability", "statement": "Machine-based information resources are persistently reviewed to ensure they are appropriately optimized for high availability and rapid recovery.", - "controls": [], + "controls": ["cp-2.5", "sc-12.1"], "updated": [ { "date": "2026-06-24", @@ -10796,7 +10880,21 @@ "KSI-CNA-RNT": { "name": "Restricting Network Traffic", "statement": "Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.", - "controls": ["ac-17.3", "ca-9", "cm-7.1", "sc-7.5", "si-8"], + "controls": [ + "ac-17.3", + "ca-9", + "cm-7.1", + "sc-7.10", + "sc-7.18", + "sc-7.20", + "sc-7.21", + "sc-7.5", + "si-10", + "si-4.11", + "si-4.18", + "si-4.4", + "si-8" + ], "updated": [ { "date": "2026-06-24", @@ -10812,7 +10910,7 @@ "KSI-CNA-RVP": { "name": "Reviewing Protections", "statement": "The effectiveness of protection against denial of service attacks and other unwanted activity for machine-based information resources is persistently reviewed.", - "controls": ["sc-5", "si-8", "si-8.2"], + "controls": ["ir-4.2", "sc-5", "sc-7.18", "si-8", "si-8.2"], "updated": [ { "date": "2026-06-24", @@ -10831,12 +10929,16 @@ "controls": [ "ac-12", "ac-17.3", + "ac-4.21", "ca-9", + "cm-11", + "sc-10", "sc-4", "sc-7", + "sc-7.20", + "sc-7.21", "sc-7.7", - "sc-8", - "sc-10" + "sc-8" ], "updated": [ { @@ -10859,15 +10961,16 @@ "name": "Automating Account Management", "statement": "The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.", "controls": [ + "ac-2.13", "ac-2.2", "ac-2.3", - "ac-2.13", "ac-6.7", - "ia-4.4", "ia-12", "ia-12.2", "ia-12.3", - "ia-12.5" + "ia-12.5", + "ia-4.4", + "ia-8.4" ], "updated": [ { @@ -10880,18 +10983,22 @@ "name": "Adopting Passwordless Methods", "statement": "Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.", "controls": [ - "ac-3", - "ia-5.1", - "ia-5.2", - "ia-5.6", - "ia-6", "ac-2", + "ac-3", "ia-2", "ia-2.1", "ia-2.2", + "ia-2.6", "ia-2.8", "ia-5", + "ia-5.1", + "ia-5.2", + "ia-5.6", + "ia-5.8", + "ia-6", "ia-8", + "ia-8.2", + "ia-8.4", "sc-23" ], "updated": [ @@ -10905,40 +11012,58 @@ "name": "Ensuring Least Privilege", "statement": "Identity and access management measures are used and persistently reviewed to ensure each user or device can only access the resources they need.", "controls": [ - "ac-2.5", - "ac-2.6", - "ac-3", - "ac-4", - "ac-6", "ac-12", "ac-14", "ac-17", "ac-17.1", "ac-17.2", "ac-17.3", + "ac-18.4", + "ac-2.11", + "ac-2.5", + "ac-2.6", + "ac-2.7", + "ac-2.9", "ac-20", "ac-20.1", + "ac-21", + "ac-3", + "ac-4", + "ac-6", + "ac-6.3", + "ac-6.8", + "au-12.3", + "au-6.7", "cm-2.7", + "cm-5.1", + "cm-5.5", + "cm-7.2", "cm-9", + "ia-11", "ia-2", "ia-3", "ia-4", "ia-4.4", "ia-5.2", "ia-5.6", - "ia-11", + "ir-4.6", + "ir-9.4", "ps-2", "ps-3", "ps-4", "ps-5", "ps-6", - "sc-4", + "ra-5.5", + "sc-2", "sc-20", "sc-21", "sc-22", "sc-23", + "sc-3", "sc-39", - "si-3" + "sc-4", + "si-3", + "si-4.19" ], "updated": [ { @@ -10952,27 +11077,38 @@ "name": "Authorizing Just-in-Time", "statement": "A least-privileged, role and attribute-based, and just-in-time security authorization model is used and persistently reviewed for all user and non-user accounts and services.", "controls": [ + "ac-17", + "ac-17.4", "ac-2", "ac-2.1", + "ac-2.11", "ac-2.2", "ac-2.3", "ac-2.4", "ac-2.6", + "ac-2.7", + "ac-20.1", + "ac-21", "ac-3", "ac-4", "ac-5", "ac-6", "ac-6.1", + "ac-6.10", "ac-6.2", + "ac-6.3", "ac-6.5", "ac-6.7", + "ac-6.8", "ac-6.9", - "ac-6.10", "ac-7", - "ac-20.1", - "ac-17", + "au-10", + "au-12.3", "au-9.4", + "ca-3.6", "cm-5", + "cm-5.1", + "cm-5.5", "cm-7", "cm-7.2", "cm-7.5", @@ -10980,6 +11116,7 @@ "ia-4", "ia-4.4", "ia-7", + "ir-4.6", "ps-2", "ps-3", "ps-4", @@ -10989,6 +11126,7 @@ "ra-5.5", "sc-2", "sc-23", + "sc-3", "sc-39" ], "updated": [ @@ -11005,8 +11143,11 @@ "controls": [ "ac-2", "ac-2.2", + "ac-2.9", "ac-4", "ac-6.5", + "au-10", + "ia-2.5", "ia-3", "ia-5.2", "ra-5.5" @@ -11025,11 +11166,24 @@ "controls": [ "ac-2", "ac-2.1", - "ac-2.3", + "ac-2.11", + "ac-2.12", "ac-2.13", + "ac-2.3", "ac-7", + "au-6.5", + "cm-5.1", + "cm-6.2", + "ir-4.2", + "ir-4.6", "ps-4", - "ps-8" + "ps-8", + "si-4", + "si-4.1", + "si-4.19", + "si-4.20", + "si-4.22", + "si-4.4" ], "updated": [ { @@ -11051,7 +11205,7 @@ "KSI-INR-AAR": { "name": "Generating After Action Reports", "statement": "Incident after action reports are generated and lessons learned are persistently incorporated.", - "controls": ["ir-3", "ir-4", "ir-4.1", "ir-8"], + "controls": ["ir-3", "ir-4", "ir-4.1", "ir-5.1", "ir-8", "ir-9.3"], "updated": [ { "date": "2026-06-24", @@ -11066,6 +11220,7 @@ "controls": [ "ir-4", "ir-4.1", + "ir-4.11", "ir-6", "ir-6.1", "ir-6.3", @@ -11073,6 +11228,7 @@ "ir-7.1", "ir-8", "ir-8.1", + "ir-9.3", "si-4.5" ], "updated": [ @@ -11086,7 +11242,17 @@ "KSI-INR-RPI": { "name": "Reviewing Past Incidents", "statement": "Past incidents are persistently reviewed for patterns or vulnerabilities that were not previously apparent or identified.", - "controls": ["ir-3", "ir-4", "ir-4.1", "ir-5", "ir-8"], + "controls": [ + "ir-3", + "ir-4", + "ir-4.1", + "ir-4.11", + "ir-4.4", + "ir-5", + "ir-5.1", + "ir-8", + "ra-5.8" + ], "updated": [ { "date": "2026-06-24", @@ -11106,7 +11272,7 @@ "indicators": { "KSI-MLA-ALA": { "name": "Authorizing Log Access", - "controls": ["si-11"], + "controls": ["au-12.3", "au-6.7", "si-11"], "updated": [ { "date": "2026-06-24", @@ -11126,7 +11292,15 @@ "KSI-MLA-EVC": { "name": "Evaluating Configurations", "statement": "The configuration of machine-based information resources, especially infrastructure as code, is persistently evaluated and tested.", - "controls": ["ca-7", "cm-2", "cm-6", "si-7.7"], + "controls": [ + "ac-19", + "ca-7", + "cm-2", + "cm-6", + "cm-6.1", + "ra-3", + "si-7.7" + ], "updated": [ { "date": "2026-06-24", @@ -11143,13 +11317,19 @@ "name": "Logging Event Types", "statement": "A list of information resources and event types that will be logged, monitored, and audited is maintained and persistently reviewed to ensure these activities occur.", "controls": [ - "ac-2.4", - "ac-6.9", "ac-17.1", + "ac-2.4", "ac-20.1", + "ac-6.9", + "au-10", + "au-12", "au-2", + "au-7", "au-7.1", - "au-12", + "cm-5.1", + "ir-9.4", + "si-4.19", + "si-4.20", "si-4.4", "si-4.5", "si-7.7" @@ -11168,22 +11348,26 @@ "controls": [ "ac-17.1", "ac-20.1", + "au-11", + "au-12.1", "au-2", "au-3", "au-3.1", "au-4", "au-5", + "au-5.1", "au-6.1", "au-6.3", + "au-6.4", + "au-6.5", "au-7", "au-7.1", "au-8", "au-9", - "au-11", "ir-4.1", + "si-4.16", "si-4.2", - "si-4.4", - "si-7.7" + "si-4.4" ], "updated": [ { @@ -11202,7 +11386,10 @@ "au-2", "au-6", "au-6.1", + "au-7", + "ra-5.8", "si-4", + "si-4.19", "si-4.4" ], "updated": [ @@ -11226,12 +11413,14 @@ "name": "Generating Inventories", "statement": "Authoritative sources are used to automatically generate real-time inventories of all information resources when needed.", "controls": [ + "cm-12", + "cm-12.1", "cm-2.2", "cm-7.5", "cm-8", "cm-8.1", - "cm-12", - "cm-12.1", + "cm-8.2", + "cm-8.4", "cp-2.8" ], "updated": [ @@ -11260,9 +11449,11 @@ "controls": [ "ac-5", "ca-2", + "ca-2.2", "cp-2.1", "cp-4.1", "ir-3.2", + "ir-4.11", "pm-3", "sa-2", "sa-3", @@ -11283,12 +11474,14 @@ "ac-5", "au-3.3", "cm-3.4", + "ia-5.7", "pl-8", "pm-7", + "ra-9", "sa-3", "sa-8", - "sc-4", "sc-18", + "sc-4", "si-10", "si-11", "si-16" @@ -11325,7 +11518,7 @@ "KSI-RPL-ABO": { "name": "Aligning Backups with Objectives", "statement": "The alignment of machine-based information resource backups with defined recovery objectives is persistently reviewed.", - "controls": ["cm-2.3", "cp-6", "cp-9", "cp-10", "cp-10.2", "si-12"], + "controls": ["cm-2.3", "cp-6", "cp-9", "cp-10", "cp-10.2"], "updated": [ { "date": "2026-06-24", @@ -11383,6 +11576,7 @@ "name": "Testing Recovery Capabilities", "statement": "The capability to recover from incidents and contingencies aligned with defined recovery objectives is persistently tested.", "controls": [ + "cp-10", "cp-2.1", "cp-2.3", "cp-4", @@ -11390,9 +11584,10 @@ "cp-6", "cp-6.1", "cp-9.1", - "cp-10", "ir-3", - "ir-3.2" + "ir-3.2", + "ir-9.3", + "sc-12.1" ], "updated": [ { @@ -11415,18 +11610,37 @@ "name": "Mitigating Supply Chain Risk", "statement": "Persistently identify, review, and mitigate potential supply chain risks.", "controls": [ + "ac-19", "ac-20", + "ca-7.4", + "ra-3", "ra-3.1", - "sa-9", "sa-10", "sa-11", + "sa-11.1", + "sa-11.2", + "sa-15", "sa-15.3", + "sa-16", + "sa-17", + "sa-21", "sa-22", + "sa-4", + "sa-4.1", + "sa-4.2", + "sa-4.5", + "sa-4.9", + "sa-9", + "sa-9.1", + "sa-9.2", + "sa-9.5", + "sc-18", "si-7.1", + "si-7.15", + "sr-2", + "sr-3", "sr-5", - "sr-6", - "ca-7.4", - "sc-18" + "sr-6" ], "updated": [ { @@ -11440,13 +11654,17 @@ "name": "Monitoring Supply Chain Risk", "statement": "Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.", "controls": [ + "ac-19", "ac-20", + "ca-2.3", "ca-3", "ir-6.3", "ps-7", + "ra-3", "ra-5", "sa-9", "si-5", + "sr-3", "sr-5", "sr-6", "sr-8" @@ -11473,14 +11691,18 @@ "statement": "The configuration of machine-based information resources is managed using automation and persistently reviewed for drift.", "controls": [ "ac-2.4", + "ac-6.8", "cm-2", "cm-2.2", "cm-2.3", "cm-6", "cm-7.1", - "pl-9", "pl-10", + "pl-9", "sa-5", + "sc-45", + "sc-45.1", + "sc-7.18", "si-5", "sr-10" ], @@ -11500,7 +11722,14 @@ "KSI-SVC-ASM": { "name": "Automating Secret Management", "statement": "Management, protection, and regular rotation of digital keys, certificates, and other secrets is automated and persistently reviewed.", - "controls": ["ac-17.2", "ia-5.2", "ia-5.6", "sc-12", "sc-17"], + "controls": [ + "ac-17.2", + "ia-5.2", + "ia-5.6", + "sc-12", + "sc-12.1", + "sc-17" + ], "updated": [ { "date": "2026-06-24", @@ -11513,12 +11742,15 @@ "name": "Evaluating and Improving Security", "statement": "Information resources are persistently evaluated for opportunities to improve security and those improvements are persistently made.", "controls": [ - "cm-7.1", + "ca-7.4", "cm-12.1", - "ma-2", + "cm-5.5", + "cm-7.1", + "ir-9.4", "pl-8", - "sc-7", + "ra-3", "sc-39", + "sc-7", "si-2.2", "si-4", "sr-10" @@ -11533,7 +11765,7 @@ }, "KSI-SVC-PRR": { "name": "Preventing Residual Risk", - "controls": ["sc-4"], + "controls": ["ac-19", "ir-9.4", "sc-12.1", "sc-4", "sc-7.18"], "updated": [ { "date": "2026-06-24", @@ -11557,7 +11789,7 @@ }, "KSI-SVC-RUD": { "name": "Removing Unwanted Data", - "controls": ["si-12.3", "si-18.4"], + "controls": ["ir-9", "si-12.3", "si-18.4", "si-8", "si-8.2"], "updated": [ { "date": "2026-06-24", @@ -11578,18 +11810,25 @@ "name": "Securing Information", "statement": "Information is encrypted or otherwise secured from unwanted access or modification.", "controls": [ - "ac-1", + "ac-11", + "ac-11.1", "ac-17.2", + "ac-19.5", + "ac-21", "cp-9.8", - "sc-8", - "sc-8.1", + "ir-9.4", "sc-13", "sc-20", "sc-21", "sc-22", "sc-23", "sc-28", - "sc-28.1" + "sc-28.1", + "sc-4", + "sc-7.18", + "sc-8", + "sc-8.1", + "si-4.18" ], "updated": [ { @@ -11600,7 +11839,15 @@ }, "KSI-SVC-VCM": { "name": "Validating Communications", - "controls": ["sc-23", "si-7.1"], + "controls": [ + "ac-10", + "ac-17.4", + "ac-18", + "ac-19", + "sc-23", + "si-4.22", + "si-7.1" + ], "updated": [ { "date": "2026-06-24", @@ -11626,13 +11873,20 @@ "name": "Validating Resource Integrity", "statement": "Use cryptographic methods to validate the integrity of machine-based information resources.", "controls": [ + "ac-17.4", + "ac-18", + "ac-19", + "au-9.3", + "cm-14", "cm-2.2", "cm-8.3", "sc-13", "sc-23", "si-7", "si-7.1", - "sr-10" + "si-7.15", + "sr-10", + "sr-11" ], "updated": [ {