Official FedRAMP Package Map
This map keeps the templates folder honest. Local Markdown and MDX files are review material; official package work should still use the current FedRAMP templates and any agency-specific instructions.
Core Authorization Package
| Artifact | Official Role | Local Source | Completion Test |
|---|---|---|---|
| System Security Plan | Main system description, boundary, architecture, control implementation, roles, and responsibilities. | 03-system-security-plan-working-outline.mdx, 04-control-implementation-matrix.mdx | SSP draft has no unowned controls or placeholder boundary claims. |
| FIPS 199 Categorization | Determines Low, Moderate, or High baseline using confidentiality, integrity, and availability. | 02-fips-199-and-boundary.mdx | AO or sponsor accepts the impact rationale. |
| Boundary Diagram | Shows authorization boundary, users, systems, external connections, and trust boundaries. | 02-fips-199-and-boundary.mdx | Diagram matches inventory and data-flow documentation. |
| Data Flow Diagram | Shows federal data movement, storage, processing, logging, and external sharing. | 02-fips-199-and-boundary.mdx, 09-access-audit-and-data-protection-plan.mdx | Every sensitive data flow has owner, control, and logging decision. |
| Control Implementation Summary | Shows implementation status, inherited controls, shared controls, gaps, and evidence. | 04-control-implementation-matrix.mdx | Every row has status, owner, evidence, and POA&M link when needed. |
| Plan of Action and Milestones | Tracks weaknesses, deficiencies, vulnerabilities, milestones, due dates, and status. | 06-poam-and-risk-register.mdx | Every known gap is tracked with owner and due date. |
| Security Assessment Plan | Defines 3PAO assessment scope, methods, sampling, schedule, and rules of engagement. | 04-control-implementation-matrix.mdx, 05-evidence-and-conmon-plan.mdx | 3PAO can trace scope to boundary and controls. |
| Security Assessment Report | Documents assessment results, findings, risk exposure, and recommendations. | 3PAO output | Findings are reconciled into POA&M. |
| Risk Exposure Table | Captures assessment weaknesses and deficiencies. | 3PAO output, 06-poam-and-risk-register.mdx | Findings tie to POA&M items and risk owner decisions. |
Continuous Monitoring Package
| Artifact | Official Role | Local Source | Completion Test |
|---|---|---|---|
| Monthly Executive Summary | Gives AO monthly posture, findings, POA&M movement, and significant changes. | 05-evidence-and-conmon-plan.mdx | Monthly package is generated from current evidence. |
| Vulnerability Scan Package | Provides OS, web app, database, container, dependency, and infrastructure scan results. | 05-evidence-and-conmon-plan.mdx, 10-ato-tooling-overview.mdx | Scans cover 100% of current inventory or approved exceptions. |
| Inventory Update | Shows current components, software, services, external systems, and ownership. | 02-fips-199-and-boundary.mdx, 15-evidence-automation-map.mdx | Inventory is updated monthly and after change. |
| POA&M Update | Shows new, open, remediated, delayed, and risk-accepted items. | 06-poam-and-risk-register.mdx | No overdue item lacks escalation or risk decision. |
| Significant Change Record | Documents major changes, affected controls, customer impact, and validation plan. | 14-operational-procedure-library.mdx | Change record exists before production impact. |
| Annual Assessment Evidence | Supports annual review and ongoing authorization. | All template docs | Evidence index proves control behavior over time. |
Supporting Plans and Policies
| Artifact | NIST Families | Local Source | Completion Test |
|---|---|---|---|
| Access Control Policy | AC, IA | 09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdx | Role matrix, access review, and privileged MFA are defined. |
| Audit and Accountability Policy | AU | 09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdx | Audit schema, retention, review, and alerting are defined. |
| Configuration Management Plan | CM | 08-secure-sdlc-and-supply-chain-plan.mdx, 13-policy-library.mdx | Baseline, change control, drift detection, and inventory are defined. |
| Contingency Plan | CP | 07-incident-contingency-and-dr-plan.mdx, 13-policy-library.mdx | Backup, restore, RTO, RPO, and exercise cadence are defined. |
| Incident Response Plan | IR | 07-incident-contingency-and-dr-plan.mdx, 13-policy-library.mdx | Roles, severity, containment, reporting, and after-action review are defined. |
| Risk Assessment Plan | RA | 06-poam-and-risk-register.mdx, 13-policy-library.mdx | Scan scope, risk scoring, remediation windows, and acceptance are defined. |
| Secure SDLC Plan | SA, SR, SI | 08-secure-sdlc-and-supply-chain-plan.mdx, 13-policy-library.mdx | CI/CD gates, SBOM, signing, provenance, and review evidence are defined. |
| Privacy and Data Protection Plan | PT, MP, SC | 09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdx | Data inventory, minimization, retention, deletion, and crypto are defined. |
| Rules of Behavior | PL, AC, AT | 13-policy-library.mdx | Users and administrators have documented acceptable-use rules. |
Transfer Rules
- Download official templates fresh before package drafting begins.
- Keep local templates files as the editable source until the agency-specific format is known.
- Transfer only reviewed statements into official templates.
- Mark unimplemented controls as planned or partial and add POA&M items.
- Keep screenshots as fallback evidence; prefer API exports, signed artifacts, logs, SARIF, JSON, OSCAL, SPDX, CycloneDX, and in-toto attestations.
Sources
| Source | Use |
|---|---|
| FedRAMP Rev 5 documents and templates | Current official template entry point. |
| FedRAMP SSP guidance | SSP expectations and package narrative guidance. |
| FedRAMP POA&M guidance | POA&M purpose, risk tracking, and template requirement. |
| FedRAMP continuous monitoring overview | Monthly inventory, POA&M, and ongoing authorization context. |
| FedRAMP Continuous Monitoring Playbook | Rev 5 ConMon expectations and scanning guidance. |