Identity and Access Management — FedRAMP KSI Domain
Generated from the official FedRAMP/rules GitHub repo. Source path:
fedramp-consolidated-rules.jsononmainat blob7d628b63fdd9. Consolidated Rules version:2026.07.02.02· upstreamlast_updated:2026-07-02. Supporting narrative documentation is available from the officialFedRAMP/2026-markdownrepository.
Identity and Access Management
Domain code: IAM · Domain ID: KSI-IAM · Web slug: identity-and-access-management
Indicators
KSI-IAM-AAM — Automating Account Management
The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.
Mapped Rev5 controls: ac-2.2, ac-2.3, ac-2.13, ac-6.7, ia-4.4, ia-12, ia-12.2, ia-12.3, ia-12.5
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-IAM-APM — Adopting Passwordless Methods
Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.
Mapped Rev5 controls: ac-3, ia-5.1, ia-5.2, ia-5.6, ia-6, ac-2, ia-2, ia-2.1, ia-2.2, ia-2.8, ia-5, ia-8, sc-23
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-IAM-ELP — Ensuring Least Privilege
Identity and access management measures are used and persistently reviewed to ensure each user or device can only access the resources they need.
Mapped Rev5 controls: ac-2.5, ac-2.6, ac-3, ac-4, ac-6, ac-12, ac-14, ac-17, ac-17.1, ac-17.2, ac-17.3, ac-20, ac-20.1, cm-2.7, cm-9, ia-2, ia-3, ia-4, ia-4.4, ia-5.2, ia-5.6, ia-11, ps-2, ps-3, ps-4, ps-5, ps-6, sc-4, sc-20, sc-21, sc-22, sc-23, sc-39, si-3
Terms: Persistently
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-IAM-JIT — Authorizing Just-in-Time
A least-privileged, role and attribute-based, and just-in-time security authorization model is used and persistently reviewed for all user and non-user accounts and services.
Mapped Rev5 controls: ac-2, ac-2.1, ac-2.2, ac-2.3, ac-2.4, ac-2.6, ac-3, ac-4, ac-5, ac-6, ac-6.1, ac-6.2, ac-6.5, ac-6.7, ac-6.9, ac-6.10, ac-7, ac-20.1, ac-17, au-9.4, cm-5, cm-7, cm-7.2, cm-7.5, cm-9, ia-4, ia-4.4, ia-7, ps-2, ps-3, ps-4, ps-5, ps-6, ps-9, ra-5.5, sc-2, sc-23, sc-39
Terms: Persistently
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-IAM-SNU — Securing Non-User Authentication
Appropriately secure authentication methods are used and persistently reviewed for non-user accounts and services.
Mapped Rev5 controls: ac-2, ac-2.2, ac-4, ac-6.5, ia-3, ia-5.2, ra-5.5
Terms: Persistently
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-IAM-SUS — Responding to Suspicious Activity
Accounts with privileged access are disabled or otherwise secured in response to suspicious activity.
Mapped Rev5 controls: ac-2, ac-2.1, ac-2.3, ac-2.13, ac-7, ps-4, ps-8
Terms: Vulnerability Response
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.