Skip to content

Policy Library

FedRAMP-ready documentation needs more than an SSP. The SSP explains how controls are implemented; policy and procedure documents explain who must do the work, how often, how evidence is retained, and how exceptions are handled.

Policy Set

PolicyFamiliesRequired DecisionsEvidence
Access Control PolicyAC, IAAccount lifecycle, role model, privileged access, remote access, separation of duties.Access reviews, IdP exports, role matrix, privileged-access logs
Audit and Accountability PolicyAUAuditable events, event schema, retention, alerting, review cadence, integrity protection.Audit schema, log retention export, alert history, review records
Awareness and Training PolicyATSecurity training scope, privileged-role training, annual acknowledgement.Training completion export, rules-of-behavior acknowledgement
Configuration Management PolicyCMBaselines, change approvals, emergency changes, drift review, inventory.Pull requests, Argo CD syncs, inventory exports, baseline scans
Contingency Planning PolicyCPRTO, RPO, backup, restore testing, alternate processing, continuity exercises.Backup logs, restore test results, DR exercise report
Incident Response PolicyIRSeverity, roles, reporting, containment, communications, after-action review.Incident tickets, timelines, notification records, lessons learned
Maintenance PolicyMAMaintenance windows, remote maintenance, tool approvals, evidence.Maintenance records, access logs, change records
Media Protection PolicyMPMedia handling, export, backup, disposal, removable media restrictions.Disposal records, backup retention, export logs
Personnel Security PolicyPSJoiner, mover, leaver, screening, termination access removal.HR-to-access tickets, deprovisioning records
Planning PolicyPLSSP ownership, rules of behavior, architecture maintenance, review cadence.SSP review issues, boundary review records, signed rules
Program Management PolicyPMRisk strategy, POA&M governance, inventory ownership, authorization cadence.Governance minutes, POA&M review, system inventory
Risk Assessment PolicyRARisk assessment cadence, vulnerability scanning, risk scoring, acceptance.Scan reports, risk register, accepted-risk records
System and Services Acquisition PolicySASecure SDLC, supplier review, development standards, testing.CI/CD reports, supplier reviews, secure coding evidence
System and Communications Protection PolicySCBoundary protection, encryption, key management, network segmentation.TLS scans, KMS config, network policy reports
System and Information Integrity PolicySIFlaw remediation, monitoring, malicious code protection, input validation.Findings, remediation tickets, alert history, validation tests
Supply Chain Risk Management PolicySRSBOM, provenance, supplier review, signed artifacts, dependency governance.SBOM, attestations, signatures, dependency update records
Privacy and PII PolicyPTAuthority to collect, minimization, consent, retention, deletion, privacy review.Data inventory, retention schedule, deletion records

Policy Template

Use this structure for each policy before transferring it into an official controlled-document format.

SectionContent
PurposeWhy the policy exists and which risk it addresses.
ScopeSystems, environments, users, data, and services covered.
Control MappingNIST 800-53 families and control IDs supported.
RolesPolicy owner, procedure owner, approver, reviewers, and evidence custodian.
RequirementsMandatory behavior in clear, testable terms.
ProceduresLink to procedures that execute the policy.
EvidenceRequired artifacts, storage location, retention, and review cadence.
ExceptionsException request path, risk owner, expiration, and compensating controls.
Review CadenceAnnual minimum and event-driven triggers.

Rules of Behavior Template

Rule AreaUser RequirementAdministrator Requirement
Account useUse assigned accounts only and protect credentials.Use privileged access only for approved administrative work.
MFAComplete required MFA and report lost authenticators.Use phishing-resistant MFA where required.
Data handlingAccess only data needed for assigned work.Do not export or copy data outside approved tools.
LoggingUnderstand that system use may be logged and reviewed.Do not disable, bypass, or tamper with logs.
Change controlDo not modify production outside approved processes.Use reviewed pull requests or emergency change process.
Incident reportingReport suspected security events immediately.Preserve evidence and follow incident command direction.
ToolingUse approved tools and repositories.Do not introduce unapproved services into the boundary.

Review Cadence

Document TypeMinimum ReviewEvent-Driven Review
PoliciesAnnualMajor architecture, data, baseline, provider, or agency requirement change
ProceduresSemiannualTooling, workflow, ownership, or evidence source change
Rules of BehaviorAnnual acknowledgementRole change or privileged-access assignment
SSP Source MaterialQuarterly while preparing ATOBoundary, control, service, or impact-level change
POA&MWeekly or monthly depending on stageNew finding, missed milestone, risk acceptance, remediation

Documentation Gaps To Close

  • Assign owner and approver for each policy.
  • Decide which policies are standalone and which are sections in a security program plan.
  • Create official controlled-document version numbers.
  • Add acknowledgement workflow for rules of behavior.
  • Link each policy to at least one procedure and at least one evidence artifact.