Use this document to lock the working strategy before writing detailed control narratives. The wrong authorization path or baseline will create rework across the SSP, POA&M, assessment plan, and continuous monitoring package.
Working Position
| Decision | Current Template Answer | Owner | Evidence Needed |
|---|
| Authorization path | Agency Authorization | [FILL IN: owner] | Sponsoring agency and AO confirmation |
| Target baseline | FedRAMP Moderate by default; High-ready technical posture where practical | [FILL IN: owner] | FIPS 199 worksheet |
| Cloud service model | SaaS with managed infrastructure and Kubernetes workloads | [FILL IN: owner] | Architecture diagram and service inventory |
| Deployment boundary | [FILL IN: production boundary] | [FILL IN: owner] | Boundary diagram |
| Data residency | United States only unless explicitly approved | [FILL IN: owner] | Hosting region list and data-flow review |
| Operator residency | US-person operations for federal boundary where required | [FILL IN: owner] | Staffing and support model |
| 3PAO | [FILL IN: candidate 3PAO] | [FILL IN: owner] | Engagement plan |
| Initial package date | [FILL IN: target date] | [FILL IN: owner] | Roadmap and POA&M burn-down |
Readiness Standard
The template goal is ATO compatibility, not an authorization claim. A control is ready only when the behavior is implemented, the owner is named, the evidence exists, and the evidence can be reproduced without manual archaeology.
Stakeholders
| Role | Name | Responsibility | Backup |
|---|
| System Owner | [FILL IN] | Owns system mission, boundary, and risk posture. | [FILL IN] |
| Authorizing Official | [FILL IN] | Accepts or rejects residual risk. | [FILL IN] |
| ISSO | [FILL IN] | Coordinates security package and control evidence. | [FILL IN] |
| ISSM | [FILL IN] | Owns security program oversight. | [FILL IN] |
| Platform Engineering Lead | [FILL IN] | Owns Kubernetes, GitOps, CI/CD, and runtime controls. | [FILL IN] |
| Application Engineering Lead | [FILL IN] | Owns application controls, tests, and release changes. | [FILL IN] |
| Privacy Lead | [FILL IN] | Owns PII inventory, minimization, retention, and privacy risk. | [FILL IN] |
| 3PAO Lead | [FILL IN] | Owns assessment planning and reporting. | [FILL IN] |
Open Assumptions
| Assumption | Why It Matters | Validation Path | Status |
|---|
| The first federal target can accept FedRAMP Moderate. | Determines baseline scope and evidence burden. | Complete FIPS 199 with agency sponsor. | Open |
| Production can run in a US-only cloud boundary. | Supports data residency and personnel requirements. | Confirm region, support, and subprocessors. | Open |
| Identity can support phishing-resistant MFA. | Required for higher-assurance identity posture. | Validate IdP and WebAuthn or PIV/CAC support. | Open |
| CI/CD can generate SBOM, provenance, and signed artifacts. | Supports supply-chain and change-control evidence. | Add pipeline controls and preserve artifacts. | Open |
| Monthly ConMon can be automated from GitHub, cluster scans, and dashboards. | Reduces ongoing authorization cost. | Define evidence exporters and storage locations. | Open |
Authorization Risks
| Risk | Impact | Mitigation | POA&M Needed |
|---|
| Boundary is unclear. | Control inheritance and assessment scope become disputed. | Create a boundary diagram and data-flow diagram before SSP drafting. | Yes |
| Evidence is manual. | Controls may be considered partially implemented. | Prefer automated scan output, signed release artifacts, and immutable logs. | Yes |
| Crypto is not FIPS validated. | SC controls may fail at Moderate or High. | Select validated modules or document inherited cloud-provider validation. | Yes |
| Access review process is not repeatable. | AC and IA controls remain partial. | Schedule quarterly access-review issues with exports attached. | Yes |
| Continuous monitoring is treated as a one-time task. | Authorization may be delayed or lost after approval. | Build monthly ConMon rhythm before assessment. | Yes |