Skip to content

Service Configuration

Automating Configuration Management

KSI-SVC-ACM

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

The configuration of machine-based information resources is managed using automation and persistently reviewed for drift.

Related SP 800-53 Controls: AC-02 (04), CM-02, CM-02 (02), CM-02 (03), CM-06, CM-07 (01), PL-09, PL-10, SA-05, SI-05, SR-10


Terms: Drift, Information Resource, Machine-Based (Information Resources), Persistently

Automating Secret Management

KSI-SVC-ASM

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

Management, protection, and regular rotation of digital keys, certificates, and other secrets is automated and persistently reviewed.

Related SP 800-53 Controls: AC-17 (02), IA-05 (02), IA-05 (06), SC-12, SC-17


Terms: Persistently, Regularly

Evaluating and Improving Security

KSI-SVC-EIS

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

Information resources are persistently evaluated for opportunities to improve security and those improvements are persistently made.

Related SP 800-53 Controls: CM-07 (01), CM-12 (01), MA-02, PL-08, SC-07, SC-39, SI-02 (02), SI-04, SR-10


Terms: Information Resource, Persistently

Preventing Residual Risk

KSI-SVC-PRR

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

Optional: Plans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data.

Plans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data.

Related SP 800-53 Controls: SC-04


Terms: Federal Customer Data, Information Resource, Likely, Persistently

Removing Unwanted Data

KSI-SVC-RUD

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

Optional: Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage.

Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage.

Related SP 800-53 Controls: SI-12 (03), SI-18 (04)


Terms: Federal Customer Data, Promptly

Securing Information

KSI-SVC-SIN

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

Information is encrypted or otherwise secured from unwanted access or modification.

Related SP 800-53 Controls: AC-01, AC-17 (02), CP-09 (08), SC-08, SC-08 (01), SC-13, SC-20, SC-21, SC-22, SC-23, SC-28, SC-28 (01)

Validating Communications

KSI-SVC-VCM

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

Optional: The authenticity and integrity of communications between machine-based information resources is persistently validated using automation.

The authenticity and integrity of communications between machine-based information resources is persistently validated using automation.

Related SP 800-53 Controls: SC-23, SI-07 (01)


Terms: Information Resource, Machine-Based (Information Resources), Persistently, Validation

Validating Resource Integrity

KSI-SVC-VRI

Changelog:

  • 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.

Use cryptographic methods to validate the integrity of machine-based information resources.

Related SP 800-53 Controls: CM-02 (02), CM-08 (03), SC-13, SC-23, SI-07, SI-07 (01), SR-10


Terms: Information Resource, Machine-Based (Information Resources), Validation

Comments