FedRAMP defines four baselines based on FIPS 199 system impact level: (a) LI-SAAS (Low Impact SaaS) - low-impact SaaS with no sensitive data + 156 controls + accelerated authorization path; (b) LOW (Low Impact) - 156 controls; (c) MODERATE (Moderate Impact) - 323 controls + applies to most federal cloud workloads handling Controlled Unclassified Information (CUI); (d) HIGH (High Impact) - 417 controls + applies to mission-critical + national-security-related cloud workloads. The baselines derive from NIST SP 800-53 Rev 5 + FedRAMP-specific parameter values (e.g. password lengths + cryptographic algorithm strengths + audit-retention periods). Baseline selection is the CSP's responsibility based on the agencies it will serve + the data classification it will process. FedRAMP Moderate is the most common baseline + applies to most federal cloud services.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.