Document Inventory
This inventory explains what to create, what to fill in, and how each draft maps to FedRAMP package expectations. Keep this file current as the template documents mature, because it becomes the checklist for turning review drafts into an authorization package.
Templates Package
| Document | Why It Exists | FedRAMP Artifact | Status |
|---|---|---|---|
01-ato-path-and-assumptions.mdx | Makes the authorization strategy explicit before control claims are written. | Agency authorization planning notes | Draft |
02-fips-199-and-boundary.mdx | Determines impact level, system boundary, data types, and inherited controls. | FIPS 199, SSP boundary sections | Draft |
03-system-security-plan-working-outline.mdx | Captures the SSP narrative in Markdown before transfer to the official template. | SSP | Draft |
04-control-implementation-matrix.mdx | Maps controls to implementation, evidence, owner, status, and gaps. | SSP Appendix A, CIS, SAP input | Draft |
05-evidence-and-conmon-plan.mdx | Defines monthly evidence production and review rhythm. | ConMon package | Draft |
06-poam-and-risk-register.mdx | Tracks weaknesses, remediation, due dates, and risk acceptance. | POA&M | Draft |
07-incident-contingency-and-dr-plan.mdx | Defines incident response, backup, continuity, and recovery expectations. | IR Plan, Contingency Plan | Draft |
08-secure-sdlc-and-supply-chain-plan.mdx | Shows how code and infrastructure changes are reviewed, scanned, signed, and released. | CM, SA, SI, SR control narrative | Draft |
09-access-audit-and-data-protection-plan.mdx | Covers identity, access, audit logs, encryption, privacy, and retention. | AC, IA, AU, SC, PT control narrative | Draft |
10-ato-tooling-overview.mdx | Lists the recommended open-source and stack-native tools with links and evidence outputs. | Tooling appendix, evidence map | Draft |
11-implementation-roadmap.mdx | Converts documentation gaps into ordered implementation work. | POA&M input, roadmap | Draft |
Official Package Crosswalk
| Official Package Area | Needed From You | Local Draft To Start From | Notes |
|---|---|---|---|
| Agency sponsor | Sponsoring agency, system owner, AO, ISSO, ISSM, and 3PAO contacts. | 01-ato-path-and-assumptions.mdx | Cannot be solved by software. |
| Impact level | FIPS 199 confidentiality, integrity, and availability impact. | 02-fips-199-and-boundary.mdx | Target Moderate until data proves Low or High. |
| Boundary | Diagrams, services, regions, users, external systems, and inherited controls. | 02-fips-199-and-boundary.mdx | Boundary drives every control statement. |
| SSP | System description, architecture, roles, control implementation, and shared responsibility. | 03-system-security-plan-working-outline.mdx | Transfer into the current official template later. |
| Control matrix | Per-control implementation status, owner, evidence, and gaps. | 04-control-implementation-matrix.mdx | Keep aligned with docs/engineering-practices/ato-control-alignment.mdx. |
| SAP | Assessment scope, methods, test artifacts, and sample plan. | 04-control-implementation-matrix.mdx, 05-evidence-and-conmon-plan.mdx | Normally drafted with the 3PAO. |
| SAR | Tested controls, findings, risk exposure, and recommendations. | 3PAO output | Do not pre-fill results before assessment. |
| POA&M | Findings, weakness source, severity, owner, milestones, and due dates. | 06-poam-and-risk-register.mdx | Keep it active from day one, not only after assessment. |
| Continuous monitoring | Monthly scans, inventory, configuration, POA&M updates, and significant-change review. | 05-evidence-and-conmon-plan.mdx | Automate evidence wherever possible. |
| IR and CP | Incident response, backup, recovery, continuity, and testing records. | 07-incident-contingency-and-dr-plan.mdx | Needs exercise evidence, not just prose. |
| Privacy | Data inventory, minimization, retention, disposal, consent, and user rights. | 09-access-audit-and-data-protection-plan.mdx | Confirm whether PII, CUI, PHI, CJIS, or payment data exists. |
Review Checklist
- Every document has an owner.
- Every placeholder is resolved or marked
[VERIFY]. - Impact level is supported by FIPS 199, not preference.
- Control claims are written as
Implemented,Partially Implemented,Planned,Inherited, orNot Applicable. - Every implemented control has evidence produced by a repeatable process.
- Every gap has a POA&M item or a documented risk decision.
- Official FedRAMP templates are downloaded fresh before submission work begins.
- No document claims the system is FedRAMP authorized before the AO decision.