FedRAMP Moderate
FedRAMP Moderate baseline. Federal cloud service authorization built on NIST SP 800-53 Rev 5 with FedRAMP-specific parameters.
FedRAMP Moderate is a compliance framework from United States with 18 domains and 323 controls that map to 288 other frameworks. The largest domains are AC - Access Control (43 controls), SC - System and Communications Protection (29 controls), CM - Configuration Management (27 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (18)
AC - Access Control
| Code | Title |
|---|---|
| AC-1 | Policy and Procedures |
| AC-11 | Device Lock |
| AC-11(1) | Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image |
| AC-12 | Session Termination |
| AC-14 | Permitted Actions Without Identification or Authentication |
| AC-17 | Remote Access |
| AC-17(1) | Monitoring and Control |
| AC-17(2) | Protection of Confidentiality and Integrity Using Encryption |
| AC-17(3) | Managed Access Control Points |
| AC-17(4) | Privileged Commands and Access |
| AC-18 | Wireless Access |
| AC-18(1) | Authentication and Encryption |
| AC-18(3) | Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment |
| AC-19 | Access Control for Mobile Devices |
| AC-19(5) | Full Device or Container-Based Encryption |
| AC-2 | Account Management |
| AC-2(1) | Automated System Account Management |
| AC-2(12) | Account Monitoring for Atypical Usage |
| AC-2(13) | Disable Accounts for High-Risk Individuals |
| AC-2(2) | Automated Temporary and Emergency Account Management |
| AC-2(3) | Disable Accounts |
| AC-2(4) | Automated Audit Actions |
| AC-2(5) | Inactivity Logout |
| AC-2(7) | Privileged User Accounts |
| AC-2(9) | Restrictions on Use of Shared and Group Accounts |
| AC-20 | Use of External Systems |
| AC-20(1) | Limits on Authorized Use |
| AC-20(2) | Portable Storage Devices Restricted Use |
| AC-21 | Information Sharing |
| AC-22 | Publicly Accessible Content |
| AC-3 | Access Enforcement |
| AC-4 | Information Flow Enforcement |
| AC-4(21) | Physical or Logical Separation of Information Flows |
| AC-5 | Separation of Duties |
| AC-6 | Least Privilege |
| AC-6(1) | Authorize Access to Security Functions |
| AC-6(10) | Prohibit Non-Privileged Users from Executing Privileged Functions |
| AC-6(2) | Non-Privileged Access for Nonsecurity Functions |
| AC-6(5) | Privileged Accounts |
| AC-6(7) | Review of User Privileges |
| AC-6(9) | Log Use of Privileged Functions |
| AC-7 | Unsuccessful Logon Attempts |
| AC-8 | System Use Notification |
AT - Awareness and Training
AU - Audit and Accountability
| Code | Title |
|---|---|
| AU-1 | Policy and Procedures |
| AU-11 | Audit Record Retention |
| AU-12 | Audit Record Generation |
| AU-2 | Event Logging |
| AU-3 | Content of Audit Records |
| AU-3(1) | Additional Audit Information |
| AU-4 | Audit Log Storage Capacity |
| AU-5 | Response to Audit Logging Process Failures |
| AU-6 | Audit Record Review, Analysis, and Reporting |
| AU-6(1) | Automated Process Integration |
| AU-6(3) | Correlate Audit Record Repositories |
| AU-7 | Audit Record Reduction and Report Generation |
| AU-7(1) | Automatic Processing |
| AU-8 | Time Stamps |
| AU-9 | Protection of Audit Information |
| AU-9(4) | Access by Subset of Privileged Users |
CA - Assessment, Authorization, and Monitoring
| Code | Title |
|---|---|
| CA-1 | Policy and Procedures |
| CA-2 | Control Assessments |
| CA-2(1) | Independent Assessors |
| CA-2(3) | Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organization] on [Assignment: organization-defined system] when the assessment meets [Assignment: organization-defined requirements] |
| CA-3 | Information Exchange |
| CA-5 | Plan of Action and Milestones |
| CA-6 | Authorization |
| CA-7 | Continuous Monitoring |
| CA-7(1) | Independent Assessment |
| CA-7(4) | Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; (b) Compliance monitoring; and (c) Change monitoring |
| CA-8 | Penetration Testing |
| CA-8(1) | Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system components |
| CA-8(2) | Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules of engagement: [Assignment: organization-defined red team exercises] |
| CA-9 | Internal System Connections |
CM - Configuration Management
| Code | Title |
|---|---|
| CM-1 | Policy and Procedures |
| CM-10 | Software Usage Restrictions |
| CM-11 | User-Installed Software |
| CM-12 | Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is processed and stored; b. Identify and document the users who have access |
| CM-12(1) | Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assignment: organization-defined system components] to ensure controls are in place to protect organizational |
| CM-2 | Baseline Configuration |
| CM-2(2) | Automation Support for Accuracy and Currency |
| CM-2(3) | Retention of Previous Configurations |
| CM-2(7) | Configure Systems and Components for High-Risk Areas |
| CM-3 | Configuration Change Control |
| CM-3(2) | Testing, Validation, and Documentation of Changes |
| CM-3(4) | Security and Privacy Representatives |
| CM-4 | Impact Analyses |
| CM-4(2) | Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements |
| CM-5 | Access Restrictions for Change |
| CM-5(1) | Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and (b) Automatically generate audit records of the enforcement actions |
| CM-5(5) | Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a production or operational environment; and (b) Review and reevaluate privileges [Assignment: |
| CM-6 | Configuration Settings |
| CM-6(1) | Automated Management, Application, and Verification |
| CM-7 | Least Functionality |
| CM-7(1) | Periodic Review |
| CM-7(2) | Prevent Program Execution |
| CM-7(5) | Authorized Software Allow-by-Exception |
| CM-8 | System Component Inventory |
| CM-8(1) | Updates During Installation and Removal |
| CM-8(3) | Automated Unauthorized Component Detection |
| CM-9 | Configuration Management Plan |
CP - Contingency Planning
| Code | Title |
|---|---|
| CP-1 | Policy and Procedures |
| CP-10 | System Recovery and Reconstitution |
| CP-10(2) | System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based |
| CP-2 | Contingency Plan |
| CP-2(1) | Coordinate with Related Plans |
| CP-2(3) | Resume Mission and Business Functions |
| CP-2(8) | Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions |
| CP-3 | Contingency Training |
| CP-4 | Contingency Plan Testing |
| CP-4(1) | Coordinate with Related Plans |
| CP-6 | Alternate Storage Site |
| CP-6(1) | Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats |
| CP-6(3) | Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions |
| CP-7 | Alternate Processing Site |
| CP-7(1) | Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats |
| CP-7(2) | Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions |
| CP-7(3) | Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives) |
| CP-8 | Telecommunications Services |
| CP-8(1) | Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and (b) Request Telecommunications Service Priority |
| CP-8(2) | Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services |
| CP-9 | System Backup |
| CP-9(1) | Testing for Reliability and Integrity |
| CP-9(8) | System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup information] |
IA - Identification and Authentication
| Code | Title |
|---|---|
| IA-1 | Policy and Procedures |
| IA-11 | Re-Authentication |
| IA-12 | Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable standards and guidelines; b. Resolve user identities to a |
| IA-12(2) | Identity Proofing | Identity Evidence. Require evidence of individual identification be presented to the registration authority |
| IA-12(3) | Identity Proofing | Identity Evidence Validation and Verification. Require that the presented identity evidence be validated and verified through [Assignment: organizational defined methods of validation and verification] |
| IA-12(5) | Identity Proofing | Address Confirmation. Require that a [Selection: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address (physical or digital) of record |
| IA-2 | Identification and Authentication (Organizational Users) |
| IA-2(1) | MFA to Privileged Accounts |
| IA-2(12) | Acceptance of PIV Credentials |
| IA-2(2) | MFA to Non-Privileged Accounts |
| IA-2(5) | Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users to be individually authenticated before granting access to the shared accounts or resources |
| IA-2(6) | Identification and Authentication (organizational Users) | Access to Accounts , separate Device. Implement multi-factor authentication for [Selection (one or more): local; network; remote] access to [Selection (one or more): privileged accounts; non-privileged accounts] such that: |
| IA-2(8) | Access to Accounts Replay Resistant |
| IA-3 | Device Identification and Authentication |
| IA-4 | Identifier Management |
| IA-4(4) | Identifier Management | Identify User Status. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status] |
| IA-5 | Authenticator Management |
| IA-5(1) | Password-Based Authentication |
| IA-5(2) | Public Key-Based Authentication |
| IA-5(6) | Protection of Authenticators |
| IA-5(7) | Authenticator Management | No Embedded Unencrypted Static Authenticators. Ensure that unencrypted static authenticators are not embedded in applications or other forms of static storage |
| IA-6 | Authentication Feedback |
| IA-7 | Cryptographic Module Authentication |
| IA-8 | Identification and Authentication (Non-Organizational Users) |
| IA-8(1) | Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies. Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies |
| IA-8(2) | Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators. (a) Accept only external authenticators that are NIST-compliant; and (b) Document and maintain a list of accepted external authenticators |
| IA-8(4) | Identification and Authentication (non-organizational Users) | Use of Defined Profiles. Conform to the following profiles for identity management [Assignment: organization-defined identity management profiles] |
IR - Incident Response
| Code | Title |
|---|---|
| IR-1 | Policy and Procedures |
| IR-2 | Incident Response Training |
| IR-3 | Incident Response Testing |
| IR-3(2) | Incident Response Testing | Coordination with Related Plans. Coordinate incident response testing with organizational elements responsible for related plans |
| IR-4 | Incident Handling |
| IR-4(1) | Automated Incident Handling Processes |
| IR-5 | Incident Monitoring |
| IR-6 | Incident Reporting |
| IR-6(1) | Automated Reporting |
| IR-6(3) | Incident Reporting | Supply Chain Coordination. Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components |
| IR-7 | Incident Response Assistance |
| IR-7(1) | Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignment: organization-defined automated mechanisms] |
| IR-8 | Incident Response Plan |
| IR-9 | Information Spillage Response. Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to information spills; b. Identifying the specific information involved in the system contamination; c. Alerting |
| IR-9(2) | Information Spillage Response | Training. Provide information spillage response training [Assignment: organization-defined frequency] |
| IR-9(3) | Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks while contaminated systems are undergoing corrective actions: [Assignment: |
| IR-9(4) | Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [Assignment: organization-defined controls] |
MA - Maintenance
| Code | Title |
|---|---|
| MA-1 | Policy and Procedures |
| MA-2 | Controlled Maintenance |
| MA-3 | Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-defined frequency] |
| MA-3(1) | Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications |
| MA-3(2) | Maintenance Tools | Inspect Media. Check media containing diagnostic and test programs for malicious code before the media are used in the system |
| MA-3(3) | Maintenance Tools | Prevent Unauthorized Removal. Prevent the removal of maintenance equipment containing organizational information by: (a) Verifying that there is no organizational information contained on the equipment; (b) Sanitizing or destroying the equipment; |
| MA-4 | Nonlocal Maintenance |
| MA-5 | Maintenance Personnel |
| MA-5(1) | Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clearances or are not U.S. citizens, that include the following requirements: (1) |
| MA-6 | Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure |
MP - Media Protection
PE - Physical and Environmental Protection
| Code | Title |
|---|---|
| PE-1 | Policy and Procedures |
| PE-10 | Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system |
| PE-11 | Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power |
| PE-12 | Emergency Lighting |
| PE-13 | Fire Protection |
| PE-13(1) | Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a |
| PE-13(2) | Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and (b) Employ an |
| PE-14 | Environmental Controls |
| PE-15 | Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel |
| PE-16 | Delivery and Removal |
| PE-17 | Alternate Work Site |
| PE-2 | Physical Access Authorizations |
| PE-3 | Physical Access Control |
| PE-4 | Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls] |
| PE-5 | Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output |
| PE-6 | Monitoring Physical Access |
| PE-6(1) | Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment. Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment |
| PE-8 | Visitor Access Records |
| PE-9 | Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction |
PL - Planning
| Code | Title |
|---|---|
| PL-1 | Policy and Procedures |
| PL-10 | Baseline Selection. Select a control baseline for the system |
| PL-11 | Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions |
| PL-2 | System Security and Privacy Plans |
| PL-4 | Rules of Behavior |
| PL-4(1) | Rules of Behavior | Social Media and External Site/application Usage Restrictions. Include in the rules of behavior, restrictions on: (a) Use of social media, social networking sites, and external sites/applications; (b) Posting organizational information |
| PL-8 | Security and Privacy Architectures |
PS - Personnel Security
| Code | Title |
|---|---|
| PS-1 | Policy and Procedures |
| PS-2 | Position Risk Designation |
| PS-3 | Personnel Screening |
| PS-3(3) | Personnel Screening | Information Requiring Special Protective Measures. Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection: (a) Have valid access authorizations that are demonstrated by assigned official government |
| PS-4 | Personnel Termination |
| PS-5 | Personnel Transfer |
| PS-6 | Access Agreements |
| PS-7 | External Personnel Security |
| PS-8 | Personnel Sanctions |
| PS-9 | Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions |
RA - Risk Assessment
| Code | Title |
|---|---|
| RA-1 | Policy and Procedures |
| RA-2 | Security Categorization |
| RA-3 | Risk Assessment |
| RA-3(1) | Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; and (b) Update the supply chain risk assessment [Assignment: organization-defined frequency], when |
| RA-5 | Vulnerability Monitoring and Scanning |
| RA-5(11) | Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components |
| RA-5(2) | Update Vulnerabilities to be Scanned |
| RA-5(3) | Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage |
| RA-5(5) | Privileged Access |
| RA-9 | Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or system services] at [Assignment: organization-defined decision points in the system development life cycle] |
| fedramp-moderate::RA-7 | Risk Response |
SA - System and Services Acquisition
| Code | Title |
|---|---|
| SA-1 | Policy and Procedures |
| SA-10 | Developer Configuration Management |
| SA-11 | Developer Testing and Evaluation |
| SA-11(1) | Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of |
| SA-11(2) | Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing |
| SA-15 | Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the |
| SA-15(3) | Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At the following decision points in the system development |
| SA-2 | Allocation of Resources |
| SA-22 | Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support |
| SA-3 | System Development Life Cycle |
| SA-4 | Acquisition Process |
| SA-4(1) | Acquisition Process | Functional Properties of Controls. Require the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be implemented |
| SA-4(10) | Use of Approved PIV Products |
| SA-4(2) | Acquisition Process | Design and Implementation Information for Controls. Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: [Selection (one or |
| SA-4(9) | Acquisition Process | Functions, Ports, Protocols, and Services in Use. Require the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organizational use |
| SA-5 | System Documentation |
| SA-8 | Security and Privacy Engineering Principles |
| SA-9 | External System Services |
| SA-9(1) | External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and (b) Verify that the acquisition or outsourcing |
| SA-9(2) | Identification of Functions, Ports, Protocols, and Services |
| SA-9(5) | External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or |
SC - System and Communications Protection
| Code | Title |
|---|---|
| SC-1 | Policy and Procedures |
| SC-10 | Network Disconnect |
| SC-12 | Cryptographic Key Establishment and Management |
| SC-13 | Cryptographic Protection |
| SC-15 | Collaborative Computing Devices and Applications |
| SC-17 | Public Key Infrastructure Certificates |
| SC-18 | Mobile Code |
| SC-2 | Separation of System and User Functionality |
| SC-20 | Secure Name/Address Resolution Service (Authoritative) |
| SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) |
| SC-22 | Architecture and Provisioning for Name/Address Resolution Service |
| SC-23 | Session Authenticity |
| SC-28 | Protection of Information at Rest |
| SC-28(1) | Cryptographic Protection |
| SC-39 | Process Isolation |
| SC-4 | Information in Shared System Resources |
| SC-45 | System Time Synchronization. Synchronize system clocks within and between systems and system components |
| SC-45(1) | System Time Synchronization | Synchronization with Authoritative Time Source. (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and (b) Synchronize the internal system clocks to the authoritative |
| SC-5 | Denial-of-Service Protection |
| SC-7 | Boundary Protection |
| SC-7(12) | Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components] |
| SC-7(18) | Boundary Protection | Fail Secure. Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device |
| SC-7(3) | Access Points |
| SC-7(4) | External Telecommunications Services |
| SC-7(5) | Deny by Default Allow by Exception |
| SC-7(7) | Split Tunneling for Remote Devices |
| SC-7(8) | Route Traffic to Authenticated Proxy Servers |
| SC-8 | Transmission Confidentiality and Integrity |
| SC-8(1) | Cryptographic Protection |
SI - System and Information Integrity
| Code | Title |
|---|---|
| SI-1 | Policy and Procedures |
| SI-10 | Information Input Validation |
| SI-11 | Error Handling |
| SI-12 | Information Management and Retention |
| SI-16 | Memory Protection |
| SI-2 | Flaw Remediation |
| SI-2(2) | Automated Flaw Remediation Status |
| SI-2(3) | Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined |
| SI-3 | Malicious Code Protection |
| SI-4 | System Monitoring |
| SI-4(1) | System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system |
| SI-4(16) | System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system |
| SI-4(18) | System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points |
| SI-4(2) | Automated Tools and Mechanisms for Real-Time Analysis |
| SI-4(23) | System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms] |
| SI-4(4) | Inbound and Outbound Communications Traffic |
| SI-4(5) | System-Generated Alerts |
| SI-5 | Security Alerts, Advisories, and Directives |
| SI-6 | Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the functions specified in SI-6a [Selection (one or more): [Assignment: organization-defined system |
| SI-7 | Software, Firmware, and Information Integrity |
| SI-7(1) | Integrity Checks |
| SI-7(7) | Integration of Detection and Response |
| SI-8 | Spam Protection |
| SI-8(2) | Spam Protection | Automatic Updates. Automatically update spam protection mechanisms [Assignment: organization-defined frequency] |
SR - Supply Chain Risk Management
| Code | Title |
|---|---|
| SR-1 | Policy and Procedures (SR-1) |
| SR-10 | Inspection of Systems or Components (SR-10) |
| SR-11 | Component Authenticity (SR-11) |
| SR-11(1) | Component Authenticity | Anti-counterfeit Training. Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, software, and firmware) |
| SR-11(2) | Component Authenticity | Configuration Control for Component Service and Repair. Maintain configuration control over the following system components awaiting service or repair and serviced or repaired components awaiting return to service: [Assignment: organization-defined system |
| SR-12 | Component Disposal (SR-12) |
| SR-2 | Supply Chain Risk Management Plan (SR-2) |
| SR-2(1) | Supply Chain Risk Management Plan | Establish SCRM Team. Establish a supply chain risk management team consisting of [Assignment: organization-defined personnel, roles, and responsibilities] to lead and support the following SCRM activities: [Assignment: organization-defined |
| SR-3 | Supply Chain Controls and Processes (SR-3) |
| SR-5 | Acquisition Strategies, Tools, and Methods (SR-5) |
| SR-6 | Supplier Assessments and Reviews (SR-6) |
| SR-8 | Notification Agreements (SR-8) |
Your Compliance Coverage
If you comply with FedRAMP Moderate, you already cover:
NIST SP 800-53 Rev 5
100%
322 controls mapped
Compare →ISO 27002:2022
98%
318 controls mapped
Compare →SOC 2
93%
301 controls mapped
Compare →+ 285 more: ISO 27001:2022 (91%), PCI DSS 4.0 (82%)
See all 288 mapped frameworks ↓Maps to 288 other frameworks
What is FedRAMP Moderate and who does it apply to?
FedRAMP Moderate is a compliance framework from United States with 18 domains and 323 controls. FedRAMP Moderate baseline. Federal cloud service authorization built on NIST SP 800-53 Rev 5 with FedRAMP-specific parameters. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does FedRAMP Moderate actually require?
FedRAMP Moderate has 323 controls organised across 18 domains. The largest domains are AC - Access Control (43 controls), SC - System and Communications Protection (29 controls), CM - Configuration Management (27 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of FedRAMP Moderate do I already cover?
FedRAMP Moderate maps to 288 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (100% coverage), ISO 27002:2022 (98% coverage), SOC 2 (93% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement FedRAMP Moderate?
Start your FedRAMP Moderate compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FedRAMP Moderate requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 323 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required