ATO Templates Book
This page combines the Storybook-visible templates pages into one review surface. Use it when you want to read the package from documentation readiness through AO risk acceptance without jumping between sidebar entries.
Combined Templates Pages
This templates area is designed to get the documentation side as close to complete as practical before execution work begins. It does not claim authorization, because a real FedRAMP ATO depends on agency sponsorship, 3PAO assessment, AO risk acceptance, current FedRAMP rules, and evidence that the documented controls actually operate.
The standard here is stronger than a checklist. A document is useful only when it states the owner, boundary, control relationship, evidence source, review cadence, and open risk decision.
Readiness Position
| Area | Target State | Current Template Artifact | Readiness |
|---|
| ATO strategy | Agency Authorization path, sponsor, AO, 3PAO, scope, assumptions. | ATO path and assumptions | Draft |
| Baseline | FIPS 199 categorization drives Low, Moderate, or High. | FIPS 199 and boundary | Draft |
| SSP | Markdown source material ready for official FedRAMP template transfer. | SSP working outline | Draft |
| Control implementation | Families mapped to implementation, evidence, tools, owner, and gaps. | Control implementation matrix | Draft |
| Evidence | ConMon package contents, retention, evidence owners, and monthly workflow. | Evidence and ConMon plan | Draft |
| Risk | POA&M fields, remediation windows, risk acceptance, and initial gaps. | POA&M and risk register | Draft |
| Operations | Incident, contingency, backup, restore, and DR exercise expectations. | Incident, contingency, and DR plan | Draft |
| Secure delivery | CI/CD, scanning, SBOM, signing, provenance, and release evidence. | Secure SDLC and supply chain plan | Draft |
| Access and data | Identity, access reviews, audit logs, crypto, privacy, and retention. | Access, audit, and data protection plan | Draft |
| Tooling | Open-source and stack-native tools mapped to evidence and controls. | ATO tooling overview | Draft |
| Roadmap | Documentation-to-execution sequence. | Implementation roadmap | Draft |
Storybook Templates Pages
Definition of Documentation Ready
Boundaries of This Package
This package makes the documentation and execution roadmap ready for review. It does not replace official FedRAMP templates, 3PAO testing, agency-specific requirements, provider inheritance evidence, or actual implementation evidence from running systems.
This map keeps the templates folder honest. Local Markdown and MDX files are review material; official package work should still use the current FedRAMP templates and any agency-specific instructions.
Core Authorization Package
| Artifact | Official Role | Local Source | Completion Test |
|---|
| System Security Plan | Main system description, boundary, architecture, control implementation, roles, and responsibilities. | 03-system-security-plan-working-outline.mdx, 04-control-implementation-matrix.mdx | SSP draft has no unowned controls or placeholder boundary claims. |
| FIPS 199 Categorization | Determines Low, Moderate, or High baseline using confidentiality, integrity, and availability. | 02-fips-199-and-boundary.mdx | AO or sponsor accepts the impact rationale. |
| Boundary Diagram | Shows authorization boundary, users, systems, external connections, and trust boundaries. | 02-fips-199-and-boundary.mdx | Diagram matches inventory and data-flow documentation. |
| Data Flow Diagram | Shows federal data movement, storage, processing, logging, and external sharing. | 02-fips-199-and-boundary.mdx, 09-access-audit-and-data-protection-plan.mdx | Every sensitive data flow has owner, control, and logging decision. |
| Control Implementation Summary | Shows implementation status, inherited controls, shared controls, gaps, and evidence. | 04-control-implementation-matrix.mdx | Every row has status, owner, evidence, and POA&M link when needed. |
| Plan of Action and Milestones | Tracks weaknesses, deficiencies, vulnerabilities, milestones, due dates, and status. | 06-poam-and-risk-register.mdx | Every known gap is tracked with owner and due date. |
| Security Assessment Plan | Defines 3PAO assessment scope, methods, sampling, schedule, and rules of engagement. | 04-control-implementation-matrix.mdx, 05-evidence-and-conmon-plan.mdx | 3PAO can trace scope to boundary and controls. |
| Security Assessment Report | Documents assessment results, findings, risk exposure, and recommendations. | 3PAO output | Findings are reconciled into POA&M. |
| Risk Exposure Table | Captures assessment weaknesses and deficiencies. | 3PAO output, 06-poam-and-risk-register.mdx | Findings tie to POA&M items and risk owner decisions. |
Continuous Monitoring Package
| Artifact | Official Role | Local Source | Completion Test |
|---|
| Monthly Executive Summary | Gives AO monthly posture, findings, POA&M movement, and significant changes. | 05-evidence-and-conmon-plan.mdx | Monthly package is generated from current evidence. |
| Vulnerability Scan Package | Provides OS, web app, database, container, dependency, and infrastructure scan results. | 05-evidence-and-conmon-plan.mdx, 10-ato-tooling-overview.mdx | Scans cover 100% of current inventory or approved exceptions. |
| Inventory Update | Shows current components, software, services, external systems, and ownership. | 02-fips-199-and-boundary.mdx, 15-evidence-automation-map.mdx | Inventory is updated monthly and after change. |
| POA&M Update | Shows new, open, remediated, delayed, and risk-accepted items. | 06-poam-and-risk-register.mdx | No overdue item lacks escalation or risk decision. |
| Significant Change Record | Documents major changes, affected controls, customer impact, and validation plan. | 14-operational-procedure-library.mdx | Change record exists before production impact. |
| Annual Assessment Evidence | Supports annual review and ongoing authorization. | All template docs | Evidence index proves control behavior over time. |
Supporting Plans and Policies
| Artifact | NIST Families | Local Source | Completion Test |
|---|
| Access Control Policy | AC, IA | 09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdx | Role matrix, access review, and privileged MFA are defined. |
| Audit and Accountability Policy | AU | 09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdx | Audit schema, retention, review, and alerting are defined. |
| Configuration Management Plan | CM | 08-secure-sdlc-and-supply-chain-plan.mdx, 13-policy-library.mdx | Baseline, change control, drift detection, and inventory are defined. |
| Contingency Plan | CP | 07-incident-contingency-and-dr-plan.mdx, 13-policy-library.mdx | Backup, restore, RTO, RPO, and exercise cadence are defined. |
| Incident Response Plan | IR | 07-incident-contingency-and-dr-plan.mdx, 13-policy-library.mdx | Roles, severity, containment, reporting, and after-action review are defined. |
| Risk Assessment Plan | RA | 06-poam-and-risk-register.mdx, 13-policy-library.mdx | Scan scope, risk scoring, remediation windows, and acceptance are defined. |
| Secure SDLC Plan | SA, SR, SI | 08-secure-sdlc-and-supply-chain-plan.mdx, 13-policy-library.mdx | CI/CD gates, SBOM, signing, provenance, and review evidence are defined. |
| Privacy and Data Protection Plan | PT, MP, SC | 09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdx | Data inventory, minimization, retention, deletion, and crypto are defined. |
| Rules of Behavior | PL, AC, AT | 13-policy-library.mdx | Users and administrators have documented acceptable-use rules. |
Transfer Rules
- Download official templates fresh before package drafting begins.
- Keep local templates files as the editable source until the agency-specific format is known.
- Transfer only reviewed statements into official templates.
- Mark unimplemented controls as planned or partial and add POA&M items.
- Keep screenshots as fallback evidence; prefer API exports, signed artifacts, logs, SARIF, JSON, OSCAL, SPDX, CycloneDX, and in-toto attestations.
Sources
FedRAMP-ready documentation needs more than an SSP. The SSP explains how controls are implemented; policy and procedure documents explain who must do the work, how often, how evidence is retained, and how exceptions are handled.
Policy Set
| Policy | Families | Required Decisions | Evidence |
|---|
| Access Control Policy | AC, IA | Account lifecycle, role model, privileged access, remote access, separation of duties. | Access reviews, IdP exports, role matrix, privileged-access logs |
| Audit and Accountability Policy | AU | Auditable events, event schema, retention, alerting, review cadence, integrity protection. | Audit schema, log retention export, alert history, review records |
| Awareness and Training Policy | AT | Security training scope, privileged-role training, annual acknowledgement. | Training completion export, rules-of-behavior acknowledgement |
| Configuration Management Policy | CM | Baselines, change approvals, emergency changes, drift review, inventory. | Pull requests, Argo CD syncs, inventory exports, baseline scans |
| Contingency Planning Policy | CP | RTO, RPO, backup, restore testing, alternate processing, continuity exercises. | Backup logs, restore test results, DR exercise report |
| Incident Response Policy | IR | Severity, roles, reporting, containment, communications, after-action review. | Incident tickets, timelines, notification records, lessons learned |
| Maintenance Policy | MA | Maintenance windows, remote maintenance, tool approvals, evidence. | Maintenance records, access logs, change records |
| Media Protection Policy | MP | Media handling, export, backup, disposal, removable media restrictions. | Disposal records, backup retention, export logs |
| Personnel Security Policy | PS | Joiner, mover, leaver, screening, termination access removal. | HR-to-access tickets, deprovisioning records |
| Planning Policy | PL | SSP ownership, rules of behavior, architecture maintenance, review cadence. | SSP review issues, boundary review records, signed rules |
| Program Management Policy | PM | Risk strategy, POA&M governance, inventory ownership, authorization cadence. | Governance minutes, POA&M review, system inventory |
| Risk Assessment Policy | RA | Risk assessment cadence, vulnerability scanning, risk scoring, acceptance. | Scan reports, risk register, accepted-risk records |
| System and Services Acquisition Policy | SA | Secure SDLC, supplier review, development standards, testing. | CI/CD reports, supplier reviews, secure coding evidence |
| System and Communications Protection Policy | SC | Boundary protection, encryption, key management, network segmentation. | TLS scans, KMS config, network policy reports |
| System and Information Integrity Policy | SI | Flaw remediation, monitoring, malicious code protection, input validation. | Findings, remediation tickets, alert history, validation tests |
| Supply Chain Risk Management Policy | SR | SBOM, provenance, supplier review, signed artifacts, dependency governance. | SBOM, attestations, signatures, dependency update records |
| Privacy and PII Policy | PT | Authority to collect, minimization, consent, retention, deletion, privacy review. | Data inventory, retention schedule, deletion records |
Policy Template
Use this structure for each policy before transferring it into an official controlled-document format.
| Section | Content |
|---|
| Purpose | Why the policy exists and which risk it addresses. |
| Scope | Systems, environments, users, data, and services covered. |
| Control Mapping | NIST 800-53 families and control IDs supported. |
| Roles | Policy owner, procedure owner, approver, reviewers, and evidence custodian. |
| Requirements | Mandatory behavior in clear, testable terms. |
| Procedures | Link to procedures that execute the policy. |
| Evidence | Required artifacts, storage location, retention, and review cadence. |
| Exceptions | Exception request path, risk owner, expiration, and compensating controls. |
| Review Cadence | Annual minimum and event-driven triggers. |
Rules of Behavior Template
| Rule Area | User Requirement | Administrator Requirement |
|---|
| Account use | Use assigned accounts only and protect credentials. | Use privileged access only for approved administrative work. |
| MFA | Complete required MFA and report lost authenticators. | Use phishing-resistant MFA where required. |
| Data handling | Access only data needed for assigned work. | Do not export or copy data outside approved tools. |
| Logging | Understand that system use may be logged and reviewed. | Do not disable, bypass, or tamper with logs. |
| Change control | Do not modify production outside approved processes. | Use reviewed pull requests or emergency change process. |
| Incident reporting | Report suspected security events immediately. | Preserve evidence and follow incident command direction. |
| Tooling | Use approved tools and repositories. | Do not introduce unapproved services into the boundary. |
Review Cadence
| Document Type | Minimum Review | Event-Driven Review |
|---|
| Policies | Annual | Major architecture, data, baseline, provider, or agency requirement change |
| Procedures | Semiannual | Tooling, workflow, ownership, or evidence source change |
| Rules of Behavior | Annual acknowledgement | Role change or privileged-access assignment |
| SSP Source Material | Quarterly while preparing ATO | Boundary, control, service, or impact-level change |
| POA&M | Weekly or monthly depending on stage | New finding, missed milestone, risk acceptance, remediation |
Documentation Gaps To Close
Procedures are where documentation becomes executable. Each procedure should be short enough to run during real work and specific enough to produce evidence an assessor can inspect.
Required Procedures
| Procedure | Families | Trigger | Evidence |
|---|
| Monthly ConMon Review | CA, RA, CM, SI | First business week of each month. | ConMon issue, scan reports, inventory, POA&M update |
| Vulnerability Scan Triage | RA, SI | New scan output or monthly package. | Triage notes, POA&M items, false-positive approvals |
| Access Review | AC, IA | Monthly for privileged access; quarterly for broader access. | Access-review issue, exports, removals |
| Joiner-Mover-Leaver | AC, IA, PS | Personnel change. | Access request, approval, provisioning or deprovisioning log |
| Break-Glass Use | AC, AU, IR | Emergency privileged access. | Incident or change ticket, audit log, post-use review |
| Production Change | CM, SA, AU | Production release or configuration change. | Pull request, approvals, CI logs, Argo CD sync |
| Emergency Change | CM, IR, AU | Urgent security or availability change. | Emergency approval, retrospective review, POA&M if needed |
| Significant Change Review | CA, CM, RA | Boundary, service, data, crypto, auth, region, or provider change. | Impact analysis, AO notification decision, validation plan |
| Backup Restore Test | CP | Quarterly or after major storage change. | Restore log, validation result, issue closure |
| Incident Response | IR, AU, SI | Security event or suspected compromise. | Incident timeline, evidence bundle, after-action report |
| Key Rotation | SC, IA, AU | Scheduled rotation or suspected exposure. | Rotation record, access review, validation |
| Audit Log Review | AU, SI | Monthly and after sensitive events. | Query results, alert review, retention status |
| Supplier Review | SR, SA, CA | New vendor, renewal, or significant change. | Supplier record, authorization evidence, risk decision |
| Data Retention Review | PT, MP, SI | Quarterly or policy change. | Data inventory update, deletion records |
Procedure Template
| Section | Content |
|---|
| Purpose | One sentence describing the control outcome. |
| Trigger | Event or cadence that starts the procedure. |
| Preconditions | Access, tools, approvals, and inputs required. |
| Steps | Ordered actions with exact systems and artifacts. |
| Evidence | Artifact name, format, storage location, and retention. |
| Failure Handling | What to do if a step cannot be completed. |
| Escalation | Who is notified and when. |
| Closure | Conditions that prove the procedure is complete. |
Significant Change Procedure
- Open a significant-change review issue.
- Describe the change, reason, customer impact, and implementation timeline.
- Identify affected controls, Key Security Indicators where applicable, data flows, inherited controls, and evidence sources.
- Complete security, privacy, platform, and application reviews.
- Decide whether AO or FedRAMP notification is required.
- Define validation, rollback, and customer communication steps.
- Attach post-change evidence.
- Update SSP, diagrams, inventory, and POA&M if needed.
Access Review Procedure
- Export current users, groups, roles, service accounts, and privileged assignments.
- Compare access against approved role matrix and ownership records.
- Remove stale, excessive, or unowned access.
- Record exceptions with owner and expiration.
- Review break-glass use since the last review.
- Attach export, removals, exceptions, and approver sign-off.
Vulnerability Triage Procedure
- Import findings from all required scanners.
- Deduplicate by package, image, host, service, or root cause.
- Assign severity using scanner severity plus exploitability and exposure.
- Create POA&M items for findings that cannot close inside the remediation window.
- Mark false positives only with evidence and expiry.
- Re-scan after remediation.
- Attach proof of closure.
Evidence Storage Rules
| Evidence Type | Preferred Format | Storage |
|---|
| Scan output | SARIF, JSON, XML, or native report | Evidence repository and scanner system |
| Approvals | Pull request, issue, or change ticket | GitHub or change-management system |
| Inventory | JSON, CSV, or generated Markdown | Evidence repository |
| Logs | Query export or immutable log reference | Log platform |
| Attestations | in-toto, SLSA, Sigstore bundle | Artifact registry |
| Diagrams | Source plus rendered image | Documentation repository |
Procedure Completion Standard
The fastest path from documentation to execution is evidence automation. The goal is to make the normal delivery pipeline produce the proof that the SSP and POA&M need.
Evidence Pipeline
| Stage | Producer | Evidence | Control Families | Storage |
|---|
| Source control | GitHub | Pull request, CODEOWNERS review, branch protection export. | AC, CM, SA | GitHub and evidence repository |
| Build | GitHub Actions | Workflow log, tests, build metadata. | CM, SA, SI | GitHub artifacts |
| Static analysis | CodeQL, Semgrep | SARIF findings. | RA, SA, SI | GitHub security and evidence repository |
| Secret scanning | gitleaks or TruffleHog | Secret scan report. | IA, SC, SI | CI artifact and security dashboard |
| Dependency scanning | Trivy, Grype, OSV-Scanner | Vulnerability report. | RA, SI, SR | CI artifact and POA&M |
| SBOM | Syft | CycloneDX or SPDX SBOM. | CM, SR | Artifact registry |
| Signing | cosign | Signature and verification output. | CM, SI, SR | Registry and evidence repository |
| Provenance | SLSA generator | in-toto attestation. | SA, SR | Registry and evidence repository |
| Deployment | Argo CD | Sync result, app health, target revision. | CM, AU | Argo CD and evidence export |
| Admission policy | Kyverno | PolicyReport and blocked admission records. | AC, CM, SC, SI | Cluster and evidence repository |
| Runtime detection | Falco | Runtime alert and triage result. | SI, IR | Alerting system |
| Observability | OpenTelemetry, Prometheus, Grafana, Loki | Metrics, traces, logs, dashboard snapshots. | AU, CA, SI | Observability stack |
| Backup | Velero, pgBackRest, provider backup | Backup and restore evidence. | CP, SC | Backup system and evidence repository |
OSCAL Automation Targets
| OSCAL Artifact | Source | Generator Candidate | Review Owner |
|---|
| Component definition | Kubernetes policies, scanners, CI/CD controls. | Compliance Trestle or hand-authored OSCAL YAML | Platform Engineering |
| SSP model | Approved SSP implementation statements. | Compliance Trestle | Security |
| Assessment plan input | Control matrix and evidence inventory. | Compliance Trestle | Security and 3PAO |
| Assessment results | Lula validation, scanner reports, 3PAO results. | Lula and 3PAO tooling | Security |
| POA&M data | Risk register and findings workflow. | GitHub Issues export or compliance system | Security |
Minimum Evidence Bundle Per Release
| Artifact | Required | Reason |
|---|
| Pull request link | Yes | Shows reviewed change and separation of duties. |
| CI workflow run | Yes | Shows test and scan execution. |
| Test report | Yes | Shows expected behavior was verified. |
| SAST report | Yes | Shows secure-development scanning. |
| Secret scan report | Yes | Shows secrets were checked before release. |
| Dependency or image scan | Yes | Shows vulnerability posture at release time. |
| SBOM | Yes | Shows software inventory for the released artifact. |
| Signature | Yes | Shows artifact integrity and origin. |
| Provenance | Yes | Shows build source and workflow. |
| Deployment record | Yes | Shows what reached production. |
Monthly Evidence Bundle
| Artifact | Required | Reason |
|---|
| Current inventory | Yes | Supports CM-8 and scan completeness. |
| Full vulnerability scan set | Yes | Supports RA-5 and SI-2. |
| POA&M update | Yes | Supports CA-5 and risk governance. |
| Access review status | Yes | Supports AC and IA controls. |
| Backup status | Yes | Supports CP controls. |
| Incident summary | Yes | Supports IR and SI controls. |
| Audit log review | Yes | Supports AU controls. |
| Significant change summary | Yes | Supports CA and CM controls. |
Automation Backlog
| Priority | Automation | Expected Gain |
|---|
| 1 | CI emits SBOM, scan reports, signatures, and provenance for every release. | Large evidence gain for SA, SI, SR, RA, and CM. |
| 2 | Monthly ConMon issue auto-populates links to scans, inventory, POA&M, and release records. | Reduces manual package assembly. |
| 3 | Kubernetes policy reports export to durable evidence storage. | Makes SC, CM, and SI control posture reviewable. |
| 4 | Access review exports are generated on schedule. | Makes AC and IA evidence repeatable. |
| 5 | OSCAL component-definition links to live validation results. | Moves toward FedRAMP 20x-ready documentation. |
Automation Definition of Done
No ATO is mathematically 100% risk-free. The realistic goal is to make the system control posture, evidence, residual risk, and remediation plan clear enough that an agency Authorizing Official can make an informed decision.
What Close To Complete Means
| Dimension | Close To Complete | Not Close Enough |
|---|
| Documentation | Every official artifact has current source material, owner, and evidence reference. | Policies exist but are generic or not tied to controls. |
| Implementation | Required controls operate in the system or are explicitly inherited. | Controls are described as future intent without POA&M. |
| Evidence | Evidence is produced by normal workflows and retained. | Evidence must be recreated manually for assessment. |
| Risk | Gaps are visible, scored, owned, and time-bound. | Gaps are hidden, vague, or unowned. |
| Agency fit | AO can see customer impact, data sensitivity, and residual risk. | Package assumes one-size-fits-all risk tolerance. |
| Input | Question It Answers | Local Source |
|---|
| FIPS 199 categorization | What baseline should apply? | 02-fips-199-and-boundary.mdx |
| Boundary and data flows | What is the AO authorizing? | 02-fips-199-and-boundary.mdx |
| SSP | How are controls implemented? | 03-system-security-plan-working-outline.mdx |
| Control matrix | Which controls are implemented, partial, inherited, or planned? | 04-control-implementation-matrix.mdx |
| Evidence index | Can the claims be verified? | 05-evidence-and-conmon-plan.mdx, 15-evidence-automation-map.mdx |
| POA&M | What risk remains and when will it be addressed? | 06-poam-and-risk-register.mdx |
| ConMon plan | How will posture stay acceptable after authorization? | 05-evidence-and-conmon-plan.mdx |
| Significant change procedure | How will risk-changing updates be handled? | 14-operational-procedure-library.mdx |
Risk Acceptance Template
| Field | Content |
|---|
| Risk ID | [FILL IN] |
| Related controls | [FILL IN] |
| System area | [FILL IN] |
| Risk statement | [FILL IN: condition, cause, consequence] |
| Severity | [FILL IN: High, Moderate, Low, Operational] |
| Current exposure | [FILL IN] |
| Compensating controls | [FILL IN] |
| Remediation plan | [FILL IN] |
| Requested acceptance period | [FILL IN] |
| Expiration date | [FILL IN] |
| Risk owner | [FILL IN] |
| AO decision | [FILL IN: Accept, reject, request remediation, request more evidence] |
Acceptable Wiggle Room
| Area | Usually Negotiable | Usually Not Negotiable |
|---|
| Timing | Remediation date for lower-risk findings. | Unowned high-risk findings. |
| Evidence format | Screenshot versus API export during early template review. | No evidence at all for implemented controls. |
| Tool choice | Equivalent scanner, SIEM, policy engine, or ticket system. | No repeatable process for scanning, logging, or access review. |
| Control inheritance | Provider-managed controls with package evidence. | Informal assumption that a provider handles a control. |
| Manual process | Time-bound manual review with owner and evidence. | Manual process with no cadence or retention. |
AO Brief Outline
- Mission and system purpose.
- Authorization boundary and baseline.
- Data sensitivity and FIPS 199 result.
- Implemented control posture.
- Inherited and shared controls.
- Evidence production model.
- Open POA&M items and remediation dates.
- Risks requested for acceptance.
- Continuous monitoring commitment.
- Significant-change and incident-reporting commitments.
Readiness Verdict
Use this verdict language internally until the package is assessed.
| Verdict | Meaning |
|---|
| Documentation Ready | The package is ready for sponsor, 3PAO, or AO review, but implementation evidence may still be partial. |
| Execution Ready | Controls are implemented and evidence is generated by normal operations. |
| Assessment Ready | Documentation, implementation, evidence, and POA&M are ready for formal 3PAO assessment. |
| Authorization Decision Ready | Assessment results, POA&M, and residual risk are ready for AO decision. |
Non-Negotiable Honesty Rule
Do not state that the system is FedRAMP compliant, FedRAMP authorized, or ATO approved from these template documents. State that the package maps to FedRAMP and NIST 800-53, that it is preparing for a target baseline, and that the final decision belongs to the agency Authorizing Official.
Use this checklist to prove the templates package covers every NIST SP 800-53 family at a documentation level. Not every family is implemented by application code, but every family needs an ownership, inheritance, applicability, or not-applicable decision.
Family Coverage
| Family | Documentation Needed | Primary Local Source | Template Status |
|---|
| AC | Access policy, role matrix, access review, privileged access, remote access, separation of duties. | 09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdx | Draft |
| AT | Awareness and training policy, role-based training, annual acknowledgement. | 13-policy-library.mdx, 19-record-template-library.mdx | Draft |
| AU | Audit policy, auditable events, schema, retention, review, alerting, integrity protection. | 09-access-audit-and-data-protection-plan.mdx, 15-evidence-automation-map.mdx | Draft |
| CA | Assessment plan inputs, ConMon process, POA&M, authorization strategy. | 01-ato-path-and-assumptions.mdx, 05-evidence-and-conmon-plan.mdx | Draft |
| CM | Baseline, inventory, change control, drift detection, emergency changes. | 08-secure-sdlc-and-supply-chain-plan.mdx, 14-operational-procedure-library.mdx | Draft |
| CP | Contingency plan, backup, restore, RTO, RPO, exercises. | 07-incident-contingency-and-dr-plan.mdx | Draft |
| IA | Identity proofing where needed, MFA, account lifecycle, service accounts, credential management. | 09-access-audit-and-data-protection-plan.mdx | Draft |
| IR | Incident response plan, severity, roles, reporting, exercises, after-action review. | 07-incident-contingency-and-dr-plan.mdx, 19-record-template-library.mdx | Draft |
| MA | Maintenance policy, maintenance windows, remote maintenance, tool approval. | 13-policy-library.mdx, 14-operational-procedure-library.mdx | Draft |
| MP | Media handling, export, backup media, disposal, removable media restrictions. | 09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdx | Draft |
| PE | Physical and environmental inheritance from cloud or facility provider. | 02-fips-199-and-boundary.mdx, 12-official-fedramp-package-map.mdx | Draft |
| PL | SSP ownership, rules of behavior, architecture, security planning. | 03-system-security-plan-working-outline.mdx, 13-policy-library.mdx | Draft |
| PM | Program governance, inventory ownership, POA&M governance, risk strategy. | 01-ato-path-and-assumptions.mdx, 06-poam-and-risk-register.mdx | Draft |
| PS | Personnel screening, joiner-mover-leaver, termination access removal. | 13-policy-library.mdx, 14-operational-procedure-library.mdx | Draft |
| PT | PII authority, minimization, consent, retention, deletion, privacy review. | 09-access-audit-and-data-protection-plan.mdx | Draft |
| RA | Risk assessment, vulnerability scanning, remediation windows, acceptance. | 06-poam-and-risk-register.mdx, 15-evidence-automation-map.mdx | Draft |
| SA | Secure SDLC, supplier review, test requirements, development standards. | 08-secure-sdlc-and-supply-chain-plan.mdx | Draft |
| SC | Boundary protection, encryption, key management, network segmentation. | 09-access-audit-and-data-protection-plan.mdx, 10-ato-tooling-overview.mdx | Draft |
| SI | Flaw remediation, monitoring, malicious code protection, integrity, validation. | 08-secure-sdlc-and-supply-chain-plan.mdx, 15-evidence-automation-map.mdx | Draft |
| SR | Supplier review, SBOM, provenance, artifact signing, dependency governance. | 08-secure-sdlc-and-supply-chain-plan.mdx, 15-evidence-automation-map.mdx | Draft |
Applicability Decisions
| Decision Type | Required When | Evidence |
|---|
| Implemented | dmwd.io owns and operates the control. | Implementation statement and repeatable evidence. |
| Shared | dmwd.io and a provider both operate part of the control. | Shared responsibility statement and provider evidence. |
| Inherited | Provider fully operates the control. | Provider authorization package or responsibility matrix. |
| Not Applicable | The control does not apply to the boundary or system model. | Rationale accepted by Security and AO or sponsor. |
| Planned | The control is required but not implemented yet. | POA&M item with owner and date. |
Coverage Audit
These record templates make the compliance work repeatable. They are deliberately small so they can become GitHub issue templates, change records, ConMon checklist items, or OSCAL-backed evidence records later.
Monthly ConMon Record
| Field | Value |
|---|
| Reporting month | [FILL IN] |
| System and environment | [FILL IN] |
| Inventory version | [FILL IN] |
| Vulnerability scans attached | [FILL IN] |
| POA&M status | [FILL IN: open, new, closed, overdue] |
| Significant changes | [FILL IN] |
| Access review status | [FILL IN] |
| Backup and restore status | [FILL IN] |
| Incidents or alerts | [FILL IN] |
| Security sign-off | [FILL IN] |
| Platform sign-off | [FILL IN] |
Access Review Record
| Field | Value |
|---|
| Review scope | [FILL IN: GitHub, IdP, Kubernetes, database, secret manager] |
| Review period | [FILL IN] |
| Export location | [FILL IN] |
| Reviewer | [FILL IN] |
| Removed access | [FILL IN] |
| Exceptions | [FILL IN] |
| Break-glass use reviewed | [FILL IN] |
| Approval | [FILL IN] |
POA&M Item Record
| Field | Value |
|---|
| POA&M ID | [FILL IN] |
| Source | [FILL IN] |
| Control | [FILL IN] |
| Weakness | [FILL IN] |
| Severity | [FILL IN] |
| Owner | [FILL IN] |
| Milestones | [FILL IN] |
| Due date | [FILL IN] |
| Status | [FILL IN] |
| Closure evidence | [FILL IN] |
Significant Change Record
| Field | Value |
|---|
| Change ID | [FILL IN] |
| Change summary | [FILL IN] |
| Reason | [FILL IN] |
| Affected services | [FILL IN] |
| Affected controls | [FILL IN] |
| Customer impact | [FILL IN] |
| Security impact analysis | [FILL IN] |
| Privacy impact analysis | [FILL IN] |
| Validation plan | [FILL IN] |
| Rollback plan | [FILL IN] |
| AO notification decision | [FILL IN] |
| Approver | [FILL IN] |
Incident Record
| Field | Value |
|---|
| Incident ID | [FILL IN] |
| Severity | [FILL IN] |
| Detection source | [FILL IN] |
| Start time | [FILL IN] |
| Incident commander | [FILL IN] |
| Affected systems | [FILL IN] |
| Data impact | [FILL IN] |
| Containment actions | [FILL IN] |
| Notifications | [FILL IN] |
| Recovery time | [FILL IN] |
| Evidence location | [FILL IN] |
| POA&M follow-ups | [FILL IN] |
Backup Restore Test Record
| Field | Value |
|---|
| Test ID | [FILL IN] |
| System | [FILL IN] |
| Backup source | [FILL IN] |
| Restore target | [FILL IN] |
| RTO target | [FILL IN] |
| RTO actual | [FILL IN] |
| RPO target | [FILL IN] |
| RPO actual | [FILL IN] |
| Validation performed | [FILL IN] |
| Issues found | [FILL IN] |
| Evidence location | [FILL IN] |
Supplier Review Record
| Field | Value |
|---|
| Supplier | [FILL IN] |
| Service | [FILL IN] |
| Boundary relationship | [FILL IN: inherited, shared, external, subprocessor] |
| Data handled | [FILL IN] |
| Authorization evidence | [FILL IN] |
| Security documentation | [FILL IN] |
| Privacy documentation | [FILL IN] |
| Exit plan | [FILL IN] |
| Renewal date | [FILL IN] |
| Risk decision | [FILL IN] |
Risk Acceptance Record
| Field | Value |
|---|
| Risk ID | [FILL IN] |
| Related POA&M ID | [FILL IN] |
| Control | [FILL IN] |
| Risk owner | [FILL IN] |
| Compensating controls | [FILL IN] |
| Acceptance period | [FILL IN] |
| Expiration date | [FILL IN] |
| AO decision | [FILL IN] |
| Review trigger | [FILL IN] |