Policy and Inventory — FedRAMP KSI Domain
Generated from the official FedRAMP/rules GitHub repo. Source path:
fedramp-consolidated-rules.jsononmainat blob7d628b63fdd9. Consolidated Rules version:2026.07.02.02· upstreamlast_updated:2026-07-02. Supporting narrative documentation is available from the officialFedRAMP/2026-markdownrepository.
Policy and Inventory
Domain code: PIY · Domain ID: KSI-PIY · Web slug: policy-and-inventory
Indicators
KSI-PIY-GIV — Generating Inventories
Authoritative sources are used to automatically generate real-time inventories of all information resources when needed.
Mapped Rev5 controls: cm-2.2, cm-7.5, cm-8, cm-8.1, cm-12, cm-12.1, cp-2.8
Terms: Information Resource
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-PIY-RES — Reviewing Executive Support
Executive support for achieving the provider’s security goals is persistently reviewed and demonstrated.
Terms: Persistently, Provider
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-PIY-RIS — Reviewing Investments in Security
The effectiveness of the provider’s investments in achieving security goals is persistently reviewed.
Mapped Rev5 controls: ac-5, ca-2, cp-2.1, cp-4.1, ir-3.2, pm-3, sa-2, sa-3, sr-2.1
Terms: Persistently, Provider
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-PIY-RSD — Reviewing Security in the SDLC
The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.
Mapped Rev5 controls: ac-5, au-3.3, cm-3.4, pl-8, pm-7, sa-3, sa-8, sc-4, sc-18, si-10, si-11, si-16
Terms: Persistently
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-PIY-RVD — Reviewing Vulnerability Disclosures
The effectiveness of the provider’s vulnerability disclosure program is persistently reviewed.
Mapped Rev5 controls: ra-5.11
Terms: Persistently, Provider, Vulnerability
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.