Skip to content
Browse docs

Policy and Inventory — FedRAMP KSI Domain

Generated from the official FedRAMP/rules GitHub repo. Source path: fedramp-consolidated-rules.json on main at blob 7d628b63fdd9. Consolidated Rules version: 2026.07.02.02 · upstream last_updated: 2026-07-02. Supporting narrative documentation is available from the official FedRAMP/2026-markdown repository.

Policy and Inventory

Domain code: PIY · Domain ID: KSI-PIY · Web slug: policy-and-inventory

Indicators

KSI-PIY-GIV — Generating Inventories

Authoritative sources are used to automatically generate real-time inventories of all information resources when needed.

Mapped Rev5 controls: cm-2.2, cm-7.5, cm-8, cm-8.1, cm-12, cm-12.1, cp-2.8

Terms: Information Resource

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

KSI-PIY-RES — Reviewing Executive Support

Executive support for achieving the provider’s security goals is persistently reviewed and demonstrated.

Terms: Persistently, Provider

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

KSI-PIY-RIS — Reviewing Investments in Security

The effectiveness of the provider’s investments in achieving security goals is persistently reviewed.

Mapped Rev5 controls: ac-5, ca-2, cp-2.1, cp-4.1, ir-3.2, pm-3, sa-2, sa-3, sr-2.1

Terms: Persistently, Provider

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

KSI-PIY-RSD — Reviewing Security in the SDLC

The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.

Mapped Rev5 controls: ac-5, au-3.3, cm-3.4, pl-8, pm-7, sa-3, sa-8, sc-4, sc-18, si-10, si-11, si-16

Terms: Persistently

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

KSI-PIY-RVD — Reviewing Vulnerability Disclosures

The effectiveness of the provider’s vulnerability disclosure program is persistently reviewed.

Mapped Rev5 controls: ra-5.11

Terms: Persistently, Provider, Vulnerability

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

URL copied to clipboard