Skip to content

Document Inventory

This inventory explains what to create, what to fill in, and how each draft maps to FedRAMP package expectations. Keep this file current as the template documents mature, because it becomes the checklist for turning review drafts into an authorization package.

Templates Package

DocumentWhy It ExistsFedRAMP ArtifactStatus
01-ato-path-and-assumptions.mdxMakes the authorization strategy explicit before control claims are written.Agency authorization planning notesDraft
02-fips-199-and-boundary.mdxDetermines impact level, system boundary, data types, and inherited controls.FIPS 199, SSP boundary sectionsDraft
03-system-security-plan-working-outline.mdxCaptures the SSP narrative in Markdown before transfer to the official template.SSPDraft
04-control-implementation-matrix.mdxMaps controls to implementation, evidence, owner, status, and gaps.SSP Appendix A, CIS, SAP inputDraft
05-evidence-and-conmon-plan.mdxDefines monthly evidence production and review rhythm.ConMon packageDraft
06-poam-and-risk-register.mdxTracks weaknesses, remediation, due dates, and risk acceptance.POA&MDraft
07-incident-contingency-and-dr-plan.mdxDefines incident response, backup, continuity, and recovery expectations.IR Plan, Contingency PlanDraft
08-secure-sdlc-and-supply-chain-plan.mdxShows how code and infrastructure changes are reviewed, scanned, signed, and released.CM, SA, SI, SR control narrativeDraft
09-access-audit-and-data-protection-plan.mdxCovers identity, access, audit logs, encryption, privacy, and retention.AC, IA, AU, SC, PT control narrativeDraft
10-ato-tooling-overview.mdxLists the recommended open-source and stack-native tools with links and evidence outputs.Tooling appendix, evidence mapDraft
11-implementation-roadmap.mdxConverts documentation gaps into ordered implementation work.POA&M input, roadmapDraft

Official Package Crosswalk

Official Package AreaNeeded From YouLocal Draft To Start FromNotes
Agency sponsorSponsoring agency, system owner, AO, ISSO, ISSM, and 3PAO contacts.01-ato-path-and-assumptions.mdxCannot be solved by software.
Impact levelFIPS 199 confidentiality, integrity, and availability impact.02-fips-199-and-boundary.mdxTarget Moderate until data proves Low or High.
BoundaryDiagrams, services, regions, users, external systems, and inherited controls.02-fips-199-and-boundary.mdxBoundary drives every control statement.
SSPSystem description, architecture, roles, control implementation, and shared responsibility.03-system-security-plan-working-outline.mdxTransfer into the current official template later.
Control matrixPer-control implementation status, owner, evidence, and gaps.04-control-implementation-matrix.mdxKeep aligned with docs/engineering-practices/ato-control-alignment.mdx.
SAPAssessment scope, methods, test artifacts, and sample plan.04-control-implementation-matrix.mdx, 05-evidence-and-conmon-plan.mdxNormally drafted with the 3PAO.
SARTested controls, findings, risk exposure, and recommendations.3PAO outputDo not pre-fill results before assessment.
POA&MFindings, weakness source, severity, owner, milestones, and due dates.06-poam-and-risk-register.mdxKeep it active from day one, not only after assessment.
Continuous monitoringMonthly scans, inventory, configuration, POA&M updates, and significant-change review.05-evidence-and-conmon-plan.mdxAutomate evidence wherever possible.
IR and CPIncident response, backup, recovery, continuity, and testing records.07-incident-contingency-and-dr-plan.mdxNeeds exercise evidence, not just prose.
PrivacyData inventory, minimization, retention, disposal, consent, and user rights.09-access-audit-and-data-protection-plan.mdxConfirm whether PII, CUI, PHI, CJIS, or payment data exists.

Review Checklist

  • Every document has an owner.
  • Every placeholder is resolved or marked [VERIFY].
  • Impact level is supported by FIPS 199, not preference.
  • Control claims are written as Implemented, Partially Implemented, Planned, Inherited, or Not Applicable.
  • Every implemented control has evidence produced by a repeatable process.
  • Every gap has a POA&M item or a documented risk decision.
  • Official FedRAMP templates are downloaded fresh before submission work begins.
  • No document claims the system is FedRAMP authorized before the AO decision.