Policy Library
FedRAMP-ready documentation needs more than an SSP. The SSP explains how controls are implemented; policy and procedure documents explain who must do the work, how often, how evidence is retained, and how exceptions are handled.
Policy Set
| Policy | Families | Required Decisions | Evidence |
|---|---|---|---|
| Access Control Policy | AC, IA | Account lifecycle, role model, privileged access, remote access, separation of duties. | Access reviews, IdP exports, role matrix, privileged-access logs |
| Audit and Accountability Policy | AU | Auditable events, event schema, retention, alerting, review cadence, integrity protection. | Audit schema, log retention export, alert history, review records |
| Awareness and Training Policy | AT | Security training scope, privileged-role training, annual acknowledgement. | Training completion export, rules-of-behavior acknowledgement |
| Configuration Management Policy | CM | Baselines, change approvals, emergency changes, drift review, inventory. | Pull requests, Argo CD syncs, inventory exports, baseline scans |
| Contingency Planning Policy | CP | RTO, RPO, backup, restore testing, alternate processing, continuity exercises. | Backup logs, restore test results, DR exercise report |
| Incident Response Policy | IR | Severity, roles, reporting, containment, communications, after-action review. | Incident tickets, timelines, notification records, lessons learned |
| Maintenance Policy | MA | Maintenance windows, remote maintenance, tool approvals, evidence. | Maintenance records, access logs, change records |
| Media Protection Policy | MP | Media handling, export, backup, disposal, removable media restrictions. | Disposal records, backup retention, export logs |
| Personnel Security Policy | PS | Joiner, mover, leaver, screening, termination access removal. | HR-to-access tickets, deprovisioning records |
| Planning Policy | PL | SSP ownership, rules of behavior, architecture maintenance, review cadence. | SSP review issues, boundary review records, signed rules |
| Program Management Policy | PM | Risk strategy, POA&M governance, inventory ownership, authorization cadence. | Governance minutes, POA&M review, system inventory |
| Risk Assessment Policy | RA | Risk assessment cadence, vulnerability scanning, risk scoring, acceptance. | Scan reports, risk register, accepted-risk records |
| System and Services Acquisition Policy | SA | Secure SDLC, supplier review, development standards, testing. | CI/CD reports, supplier reviews, secure coding evidence |
| System and Communications Protection Policy | SC | Boundary protection, encryption, key management, network segmentation. | TLS scans, KMS config, network policy reports |
| System and Information Integrity Policy | SI | Flaw remediation, monitoring, malicious code protection, input validation. | Findings, remediation tickets, alert history, validation tests |
| Supply Chain Risk Management Policy | SR | SBOM, provenance, supplier review, signed artifacts, dependency governance. | SBOM, attestations, signatures, dependency update records |
| Privacy and PII Policy | PT | Authority to collect, minimization, consent, retention, deletion, privacy review. | Data inventory, retention schedule, deletion records |
Policy Template
Use this structure for each policy before transferring it into an official controlled-document format.
| Section | Content |
|---|---|
| Purpose | Why the policy exists and which risk it addresses. |
| Scope | Systems, environments, users, data, and services covered. |
| Control Mapping | NIST 800-53 families and control IDs supported. |
| Roles | Policy owner, procedure owner, approver, reviewers, and evidence custodian. |
| Requirements | Mandatory behavior in clear, testable terms. |
| Procedures | Link to procedures that execute the policy. |
| Evidence | Required artifacts, storage location, retention, and review cadence. |
| Exceptions | Exception request path, risk owner, expiration, and compensating controls. |
| Review Cadence | Annual minimum and event-driven triggers. |
Rules of Behavior Template
| Rule Area | User Requirement | Administrator Requirement |
|---|---|---|
| Account use | Use assigned accounts only and protect credentials. | Use privileged access only for approved administrative work. |
| MFA | Complete required MFA and report lost authenticators. | Use phishing-resistant MFA where required. |
| Data handling | Access only data needed for assigned work. | Do not export or copy data outside approved tools. |
| Logging | Understand that system use may be logged and reviewed. | Do not disable, bypass, or tamper with logs. |
| Change control | Do not modify production outside approved processes. | Use reviewed pull requests or emergency change process. |
| Incident reporting | Report suspected security events immediately. | Preserve evidence and follow incident command direction. |
| Tooling | Use approved tools and repositories. | Do not introduce unapproved services into the boundary. |
Review Cadence
| Document Type | Minimum Review | Event-Driven Review |
|---|---|---|
| Policies | Annual | Major architecture, data, baseline, provider, or agency requirement change |
| Procedures | Semiannual | Tooling, workflow, ownership, or evidence source change |
| Rules of Behavior | Annual acknowledgement | Role change or privileged-access assignment |
| SSP Source Material | Quarterly while preparing ATO | Boundary, control, service, or impact-level change |
| POA&M | Weekly or monthly depending on stage | New finding, missed milestone, risk acceptance, remediation |
Documentation Gaps To Close
- Assign owner and approver for each policy.
- Decide which policies are standalone and which are sections in a security program plan.
- Create official controlled-document version numbers.
- Add acknowledgement workflow for rules of behavior.
- Link each policy to at least one procedure and at least one evidence artifact.