Skip to content

ATO Templates Book

ATO Templates Book

This page combines the Storybook-visible templates pages into one review surface. Use it when you want to read the package from documentation readiness through AO risk acceptance without jumping between sidebar entries.

Combined Templates Pages

This templates area is designed to get the documentation side as close to complete as practical before execution work begins. It does not claim authorization, because a real FedRAMP ATO depends on agency sponsorship, 3PAO assessment, AO risk acceptance, current FedRAMP rules, and evidence that the documented controls actually operate.

The standard here is stronger than a checklist. A document is useful only when it states the owner, boundary, control relationship, evidence source, review cadence, and open risk decision.

Readiness Position

AreaTarget StateCurrent Template ArtifactReadiness
ATO strategyAgency Authorization path, sponsor, AO, 3PAO, scope, assumptions.ATO path and assumptionsDraft
BaselineFIPS 199 categorization drives Low, Moderate, or High.FIPS 199 and boundaryDraft
SSPMarkdown source material ready for official FedRAMP template transfer.SSP working outlineDraft
Control implementationFamilies mapped to implementation, evidence, tools, owner, and gaps.Control implementation matrixDraft
EvidenceConMon package contents, retention, evidence owners, and monthly workflow.Evidence and ConMon planDraft
RiskPOA&M fields, remediation windows, risk acceptance, and initial gaps.POA&M and risk registerDraft
OperationsIncident, contingency, backup, restore, and DR exercise expectations.Incident, contingency, and DR planDraft
Secure deliveryCI/CD, scanning, SBOM, signing, provenance, and release evidence.Secure SDLC and supply chain planDraft
Access and dataIdentity, access reviews, audit logs, crypto, privacy, and retention.Access, audit, and data protection planDraft
ToolingOpen-source and stack-native tools mapped to evidence and controls.ATO tooling overviewDraft
RoadmapDocumentation-to-execution sequence.Implementation roadmapDraft

Storybook Templates Pages

PageUse It For
Official FedRAMP Package MapTurning local drafts into official SSP, POA&M, ConMon, SAP, SAR, IR, and contingency artifacts.
Policy LibraryDrafting the policy and procedure set that supports NIST 800-53 control families.
Operational Procedure LibraryConverting policy into repeatable operational procedures with evidence.
Evidence Automation MapDeciding what each tool must emit and where evidence is retained.
AO Risk Acceptance BriefSeparating documentation readiness from agency risk acceptance.
ATO Templates BookReading the Storybook-visible templates pages as one combined review surface.
Control Family Coverage ChecklistAuditing whether every NIST 800-53 family has a documentation decision.
Record Template LibraryCreating repeatable evidence records for recurring compliance work.

Definition of Documentation Ready

  • The FIPS 199 worksheet is complete enough to justify the target baseline.
  • The authorization boundary and data flows are explicit.
  • Every control family has a policy owner and procedure owner.
  • Every implementation statement names evidence, not only intent.
  • Every known gap appears in the POA&M templates register.
  • Every official FedRAMP artifact has a local source document.
  • Every required tool has a control purpose, evidence output, and adoption priority.
  • Every manual process has a future automation path or an accepted manual cadence.
  • The AO brief explains residual risk instead of pretending there is none.

Boundaries of This Package

This package makes the documentation and execution roadmap ready for review. It does not replace official FedRAMP templates, 3PAO testing, agency-specific requirements, provider inheritance evidence, or actual implementation evidence from running systems.

This map keeps the templates folder honest. Local Markdown and MDX files are review material; official package work should still use the current FedRAMP templates and any agency-specific instructions.

Core Authorization Package

ArtifactOfficial RoleLocal SourceCompletion Test
System Security PlanMain system description, boundary, architecture, control implementation, roles, and responsibilities.03-system-security-plan-working-outline.mdx, 04-control-implementation-matrix.mdxSSP draft has no unowned controls or placeholder boundary claims.
FIPS 199 CategorizationDetermines Low, Moderate, or High baseline using confidentiality, integrity, and availability.02-fips-199-and-boundary.mdxAO or sponsor accepts the impact rationale.
Boundary DiagramShows authorization boundary, users, systems, external connections, and trust boundaries.02-fips-199-and-boundary.mdxDiagram matches inventory and data-flow documentation.
Data Flow DiagramShows federal data movement, storage, processing, logging, and external sharing.02-fips-199-and-boundary.mdx, 09-access-audit-and-data-protection-plan.mdxEvery sensitive data flow has owner, control, and logging decision.
Control Implementation SummaryShows implementation status, inherited controls, shared controls, gaps, and evidence.04-control-implementation-matrix.mdxEvery row has status, owner, evidence, and POA&M link when needed.
Plan of Action and MilestonesTracks weaknesses, deficiencies, vulnerabilities, milestones, due dates, and status.06-poam-and-risk-register.mdxEvery known gap is tracked with owner and due date.
Security Assessment PlanDefines 3PAO assessment scope, methods, sampling, schedule, and rules of engagement.04-control-implementation-matrix.mdx, 05-evidence-and-conmon-plan.mdx3PAO can trace scope to boundary and controls.
Security Assessment ReportDocuments assessment results, findings, risk exposure, and recommendations.3PAO outputFindings are reconciled into POA&M.
Risk Exposure TableCaptures assessment weaknesses and deficiencies.3PAO output, 06-poam-and-risk-register.mdxFindings tie to POA&M items and risk owner decisions.

Continuous Monitoring Package

ArtifactOfficial RoleLocal SourceCompletion Test
Monthly Executive SummaryGives AO monthly posture, findings, POA&M movement, and significant changes.05-evidence-and-conmon-plan.mdxMonthly package is generated from current evidence.
Vulnerability Scan PackageProvides OS, web app, database, container, dependency, and infrastructure scan results.05-evidence-and-conmon-plan.mdx, 10-ato-tooling-overview.mdxScans cover 100% of current inventory or approved exceptions.
Inventory UpdateShows current components, software, services, external systems, and ownership.02-fips-199-and-boundary.mdx, 15-evidence-automation-map.mdxInventory is updated monthly and after change.
POA&M UpdateShows new, open, remediated, delayed, and risk-accepted items.06-poam-and-risk-register.mdxNo overdue item lacks escalation or risk decision.
Significant Change RecordDocuments major changes, affected controls, customer impact, and validation plan.14-operational-procedure-library.mdxChange record exists before production impact.
Annual Assessment EvidenceSupports annual review and ongoing authorization.All template docsEvidence index proves control behavior over time.

Supporting Plans and Policies

ArtifactNIST FamiliesLocal SourceCompletion Test
Access Control PolicyAC, IA09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdxRole matrix, access review, and privileged MFA are defined.
Audit and Accountability PolicyAU09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdxAudit schema, retention, review, and alerting are defined.
Configuration Management PlanCM08-secure-sdlc-and-supply-chain-plan.mdx, 13-policy-library.mdxBaseline, change control, drift detection, and inventory are defined.
Contingency PlanCP07-incident-contingency-and-dr-plan.mdx, 13-policy-library.mdxBackup, restore, RTO, RPO, and exercise cadence are defined.
Incident Response PlanIR07-incident-contingency-and-dr-plan.mdx, 13-policy-library.mdxRoles, severity, containment, reporting, and after-action review are defined.
Risk Assessment PlanRA06-poam-and-risk-register.mdx, 13-policy-library.mdxScan scope, risk scoring, remediation windows, and acceptance are defined.
Secure SDLC PlanSA, SR, SI08-secure-sdlc-and-supply-chain-plan.mdx, 13-policy-library.mdxCI/CD gates, SBOM, signing, provenance, and review evidence are defined.
Privacy and Data Protection PlanPT, MP, SC09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdxData inventory, minimization, retention, deletion, and crypto are defined.
Rules of BehaviorPL, AC, AT13-policy-library.mdxUsers and administrators have documented acceptable-use rules.

Transfer Rules

  • Download official templates fresh before package drafting begins.
  • Keep local templates files as the editable source until the agency-specific format is known.
  • Transfer only reviewed statements into official templates.
  • Mark unimplemented controls as planned or partial and add POA&M items.
  • Keep screenshots as fallback evidence; prefer API exports, signed artifacts, logs, SARIF, JSON, OSCAL, SPDX, CycloneDX, and in-toto attestations.

Sources

SourceUse
FedRAMP Rev 5 documents and templatesCurrent official template entry point.
FedRAMP SSP guidanceSSP expectations and package narrative guidance.
FedRAMP POA&M guidancePOA&M purpose, risk tracking, and template requirement.
FedRAMP continuous monitoring overviewMonthly inventory, POA&M, and ongoing authorization context.
FedRAMP Continuous Monitoring PlaybookRev 5 ConMon expectations and scanning guidance.

FedRAMP-ready documentation needs more than an SSP. The SSP explains how controls are implemented; policy and procedure documents explain who must do the work, how often, how evidence is retained, and how exceptions are handled.

Policy Set

PolicyFamiliesRequired DecisionsEvidence
Access Control PolicyAC, IAAccount lifecycle, role model, privileged access, remote access, separation of duties.Access reviews, IdP exports, role matrix, privileged-access logs
Audit and Accountability PolicyAUAuditable events, event schema, retention, alerting, review cadence, integrity protection.Audit schema, log retention export, alert history, review records
Awareness and Training PolicyATSecurity training scope, privileged-role training, annual acknowledgement.Training completion export, rules-of-behavior acknowledgement
Configuration Management PolicyCMBaselines, change approvals, emergency changes, drift review, inventory.Pull requests, Argo CD syncs, inventory exports, baseline scans
Contingency Planning PolicyCPRTO, RPO, backup, restore testing, alternate processing, continuity exercises.Backup logs, restore test results, DR exercise report
Incident Response PolicyIRSeverity, roles, reporting, containment, communications, after-action review.Incident tickets, timelines, notification records, lessons learned
Maintenance PolicyMAMaintenance windows, remote maintenance, tool approvals, evidence.Maintenance records, access logs, change records
Media Protection PolicyMPMedia handling, export, backup, disposal, removable media restrictions.Disposal records, backup retention, export logs
Personnel Security PolicyPSJoiner, mover, leaver, screening, termination access removal.HR-to-access tickets, deprovisioning records
Planning PolicyPLSSP ownership, rules of behavior, architecture maintenance, review cadence.SSP review issues, boundary review records, signed rules
Program Management PolicyPMRisk strategy, POA&M governance, inventory ownership, authorization cadence.Governance minutes, POA&M review, system inventory
Risk Assessment PolicyRARisk assessment cadence, vulnerability scanning, risk scoring, acceptance.Scan reports, risk register, accepted-risk records
System and Services Acquisition PolicySASecure SDLC, supplier review, development standards, testing.CI/CD reports, supplier reviews, secure coding evidence
System and Communications Protection PolicySCBoundary protection, encryption, key management, network segmentation.TLS scans, KMS config, network policy reports
System and Information Integrity PolicySIFlaw remediation, monitoring, malicious code protection, input validation.Findings, remediation tickets, alert history, validation tests
Supply Chain Risk Management PolicySRSBOM, provenance, supplier review, signed artifacts, dependency governance.SBOM, attestations, signatures, dependency update records
Privacy and PII PolicyPTAuthority to collect, minimization, consent, retention, deletion, privacy review.Data inventory, retention schedule, deletion records

Policy Template

Use this structure for each policy before transferring it into an official controlled-document format.

SectionContent
PurposeWhy the policy exists and which risk it addresses.
ScopeSystems, environments, users, data, and services covered.
Control MappingNIST 800-53 families and control IDs supported.
RolesPolicy owner, procedure owner, approver, reviewers, and evidence custodian.
RequirementsMandatory behavior in clear, testable terms.
ProceduresLink to procedures that execute the policy.
EvidenceRequired artifacts, storage location, retention, and review cadence.
ExceptionsException request path, risk owner, expiration, and compensating controls.
Review CadenceAnnual minimum and event-driven triggers.

Rules of Behavior Template

Rule AreaUser RequirementAdministrator Requirement
Account useUse assigned accounts only and protect credentials.Use privileged access only for approved administrative work.
MFAComplete required MFA and report lost authenticators.Use phishing-resistant MFA where required.
Data handlingAccess only data needed for assigned work.Do not export or copy data outside approved tools.
LoggingUnderstand that system use may be logged and reviewed.Do not disable, bypass, or tamper with logs.
Change controlDo not modify production outside approved processes.Use reviewed pull requests or emergency change process.
Incident reportingReport suspected security events immediately.Preserve evidence and follow incident command direction.
ToolingUse approved tools and repositories.Do not introduce unapproved services into the boundary.

Review Cadence

Document TypeMinimum ReviewEvent-Driven Review
PoliciesAnnualMajor architecture, data, baseline, provider, or agency requirement change
ProceduresSemiannualTooling, workflow, ownership, or evidence source change
Rules of BehaviorAnnual acknowledgementRole change or privileged-access assignment
SSP Source MaterialQuarterly while preparing ATOBoundary, control, service, or impact-level change
POA&MWeekly or monthly depending on stageNew finding, missed milestone, risk acceptance, remediation

Documentation Gaps To Close

  • Assign owner and approver for each policy.
  • Decide which policies are standalone and which are sections in a security program plan.
  • Create official controlled-document version numbers.
  • Add acknowledgement workflow for rules of behavior.
  • Link each policy to at least one procedure and at least one evidence artifact.

Procedures are where documentation becomes executable. Each procedure should be short enough to run during real work and specific enough to produce evidence an assessor can inspect.

Required Procedures

ProcedureFamiliesTriggerEvidence
Monthly ConMon ReviewCA, RA, CM, SIFirst business week of each month.ConMon issue, scan reports, inventory, POA&M update
Vulnerability Scan TriageRA, SINew scan output or monthly package.Triage notes, POA&M items, false-positive approvals
Access ReviewAC, IAMonthly for privileged access; quarterly for broader access.Access-review issue, exports, removals
Joiner-Mover-LeaverAC, IA, PSPersonnel change.Access request, approval, provisioning or deprovisioning log
Break-Glass UseAC, AU, IREmergency privileged access.Incident or change ticket, audit log, post-use review
Production ChangeCM, SA, AUProduction release or configuration change.Pull request, approvals, CI logs, Argo CD sync
Emergency ChangeCM, IR, AUUrgent security or availability change.Emergency approval, retrospective review, POA&M if needed
Significant Change ReviewCA, CM, RABoundary, service, data, crypto, auth, region, or provider change.Impact analysis, AO notification decision, validation plan
Backup Restore TestCPQuarterly or after major storage change.Restore log, validation result, issue closure
Incident ResponseIR, AU, SISecurity event or suspected compromise.Incident timeline, evidence bundle, after-action report
Key RotationSC, IA, AUScheduled rotation or suspected exposure.Rotation record, access review, validation
Audit Log ReviewAU, SIMonthly and after sensitive events.Query results, alert review, retention status
Supplier ReviewSR, SA, CANew vendor, renewal, or significant change.Supplier record, authorization evidence, risk decision
Data Retention ReviewPT, MP, SIQuarterly or policy change.Data inventory update, deletion records

Procedure Template

SectionContent
PurposeOne sentence describing the control outcome.
TriggerEvent or cadence that starts the procedure.
PreconditionsAccess, tools, approvals, and inputs required.
StepsOrdered actions with exact systems and artifacts.
EvidenceArtifact name, format, storage location, and retention.
Failure HandlingWhat to do if a step cannot be completed.
EscalationWho is notified and when.
ClosureConditions that prove the procedure is complete.

Significant Change Procedure

  1. Open a significant-change review issue.
  2. Describe the change, reason, customer impact, and implementation timeline.
  3. Identify affected controls, Key Security Indicators where applicable, data flows, inherited controls, and evidence sources.
  4. Complete security, privacy, platform, and application reviews.
  5. Decide whether AO or FedRAMP notification is required.
  6. Define validation, rollback, and customer communication steps.
  7. Attach post-change evidence.
  8. Update SSP, diagrams, inventory, and POA&M if needed.

Access Review Procedure

  1. Export current users, groups, roles, service accounts, and privileged assignments.
  2. Compare access against approved role matrix and ownership records.
  3. Remove stale, excessive, or unowned access.
  4. Record exceptions with owner and expiration.
  5. Review break-glass use since the last review.
  6. Attach export, removals, exceptions, and approver sign-off.

Vulnerability Triage Procedure

  1. Import findings from all required scanners.
  2. Deduplicate by package, image, host, service, or root cause.
  3. Assign severity using scanner severity plus exploitability and exposure.
  4. Create POA&M items for findings that cannot close inside the remediation window.
  5. Mark false positives only with evidence and expiry.
  6. Re-scan after remediation.
  7. Attach proof of closure.

Evidence Storage Rules

Evidence TypePreferred FormatStorage
Scan outputSARIF, JSON, XML, or native reportEvidence repository and scanner system
ApprovalsPull request, issue, or change ticketGitHub or change-management system
InventoryJSON, CSV, or generated MarkdownEvidence repository
LogsQuery export or immutable log referenceLog platform
Attestationsin-toto, SLSA, Sigstore bundleArtifact registry
DiagramsSource plus rendered imageDocumentation repository

Procedure Completion Standard

  • Procedure run has a named owner.
  • Inputs and outputs are attached or linked.
  • Exceptions have a risk owner and expiration.
  • Any failed step creates a POA&M item or incident.
  • Evidence is retained in the expected location.

The fastest path from documentation to execution is evidence automation. The goal is to make the normal delivery pipeline produce the proof that the SSP and POA&M need.

Evidence Pipeline

StageProducerEvidenceControl FamiliesStorage
Source controlGitHubPull request, CODEOWNERS review, branch protection export.AC, CM, SAGitHub and evidence repository
BuildGitHub ActionsWorkflow log, tests, build metadata.CM, SA, SIGitHub artifacts
Static analysisCodeQL, SemgrepSARIF findings.RA, SA, SIGitHub security and evidence repository
Secret scanninggitleaks or TruffleHogSecret scan report.IA, SC, SICI artifact and security dashboard
Dependency scanningTrivy, Grype, OSV-ScannerVulnerability report.RA, SI, SRCI artifact and POA&M
SBOMSyftCycloneDX or SPDX SBOM.CM, SRArtifact registry
SigningcosignSignature and verification output.CM, SI, SRRegistry and evidence repository
ProvenanceSLSA generatorin-toto attestation.SA, SRRegistry and evidence repository
DeploymentArgo CDSync result, app health, target revision.CM, AUArgo CD and evidence export
Admission policyKyvernoPolicyReport and blocked admission records.AC, CM, SC, SICluster and evidence repository
Runtime detectionFalcoRuntime alert and triage result.SI, IRAlerting system
ObservabilityOpenTelemetry, Prometheus, Grafana, LokiMetrics, traces, logs, dashboard snapshots.AU, CA, SIObservability stack
BackupVelero, pgBackRest, provider backupBackup and restore evidence.CP, SCBackup system and evidence repository

OSCAL Automation Targets

OSCAL ArtifactSourceGenerator CandidateReview Owner
Component definitionKubernetes policies, scanners, CI/CD controls.Compliance Trestle or hand-authored OSCAL YAMLPlatform Engineering
SSP modelApproved SSP implementation statements.Compliance TrestleSecurity
Assessment plan inputControl matrix and evidence inventory.Compliance TrestleSecurity and 3PAO
Assessment resultsLula validation, scanner reports, 3PAO results.Lula and 3PAO toolingSecurity
POA&M dataRisk register and findings workflow.GitHub Issues export or compliance systemSecurity

Minimum Evidence Bundle Per Release

ArtifactRequiredReason
Pull request linkYesShows reviewed change and separation of duties.
CI workflow runYesShows test and scan execution.
Test reportYesShows expected behavior was verified.
SAST reportYesShows secure-development scanning.
Secret scan reportYesShows secrets were checked before release.
Dependency or image scanYesShows vulnerability posture at release time.
SBOMYesShows software inventory for the released artifact.
SignatureYesShows artifact integrity and origin.
ProvenanceYesShows build source and workflow.
Deployment recordYesShows what reached production.

Monthly Evidence Bundle

ArtifactRequiredReason
Current inventoryYesSupports CM-8 and scan completeness.
Full vulnerability scan setYesSupports RA-5 and SI-2.
POA&M updateYesSupports CA-5 and risk governance.
Access review statusYesSupports AC and IA controls.
Backup statusYesSupports CP controls.
Incident summaryYesSupports IR and SI controls.
Audit log reviewYesSupports AU controls.
Significant change summaryYesSupports CA and CM controls.

Automation Backlog

PriorityAutomationExpected Gain
1CI emits SBOM, scan reports, signatures, and provenance for every release.Large evidence gain for SA, SI, SR, RA, and CM.
2Monthly ConMon issue auto-populates links to scans, inventory, POA&M, and release records.Reduces manual package assembly.
3Kubernetes policy reports export to durable evidence storage.Makes SC, CM, and SI control posture reviewable.
4Access review exports are generated on schedule.Makes AC and IA evidence repeatable.
5OSCAL component-definition links to live validation results.Moves toward FedRAMP 20x-ready documentation.

Automation Definition of Done

  • Evidence is generated without manual copy-paste.
  • Evidence includes system, environment, timestamp, commit or artifact, and owner.
  • Evidence is retained outside short-lived CI logs when needed.
  • Evidence maps to at least one control family.
  • Evidence failure creates an issue, alert, POA&M item, or release block.

No ATO is mathematically 100% risk-free. The realistic goal is to make the system control posture, evidence, residual risk, and remediation plan clear enough that an agency Authorizing Official can make an informed decision.

What Close To Complete Means

DimensionClose To CompleteNot Close Enough
DocumentationEvery official artifact has current source material, owner, and evidence reference.Policies exist but are generic or not tied to controls.
ImplementationRequired controls operate in the system or are explicitly inherited.Controls are described as future intent without POA&M.
EvidenceEvidence is produced by normal workflows and retained.Evidence must be recreated manually for assessment.
RiskGaps are visible, scored, owned, and time-bound.Gaps are hidden, vague, or unowned.
Agency fitAO can see customer impact, data sensitivity, and residual risk.Package assumes one-size-fits-all risk tolerance.

AO Decision Inputs

InputQuestion It AnswersLocal Source
FIPS 199 categorizationWhat baseline should apply?02-fips-199-and-boundary.mdx
Boundary and data flowsWhat is the AO authorizing?02-fips-199-and-boundary.mdx
SSPHow are controls implemented?03-system-security-plan-working-outline.mdx
Control matrixWhich controls are implemented, partial, inherited, or planned?04-control-implementation-matrix.mdx
Evidence indexCan the claims be verified?05-evidence-and-conmon-plan.mdx, 15-evidence-automation-map.mdx
POA&MWhat risk remains and when will it be addressed?06-poam-and-risk-register.mdx
ConMon planHow will posture stay acceptable after authorization?05-evidence-and-conmon-plan.mdx
Significant change procedureHow will risk-changing updates be handled?14-operational-procedure-library.mdx

Risk Acceptance Template

FieldContent
Risk ID[FILL IN]
Related controls[FILL IN]
System area[FILL IN]
Risk statement[FILL IN: condition, cause, consequence]
Severity[FILL IN: High, Moderate, Low, Operational]
Current exposure[FILL IN]
Compensating controls[FILL IN]
Remediation plan[FILL IN]
Requested acceptance period[FILL IN]
Expiration date[FILL IN]
Risk owner[FILL IN]
AO decision[FILL IN: Accept, reject, request remediation, request more evidence]

Acceptable Wiggle Room

AreaUsually NegotiableUsually Not Negotiable
TimingRemediation date for lower-risk findings.Unowned high-risk findings.
Evidence formatScreenshot versus API export during early template review.No evidence at all for implemented controls.
Tool choiceEquivalent scanner, SIEM, policy engine, or ticket system.No repeatable process for scanning, logging, or access review.
Control inheritanceProvider-managed controls with package evidence.Informal assumption that a provider handles a control.
Manual processTime-bound manual review with owner and evidence.Manual process with no cadence or retention.

AO Brief Outline

  1. Mission and system purpose.
  2. Authorization boundary and baseline.
  3. Data sensitivity and FIPS 199 result.
  4. Implemented control posture.
  5. Inherited and shared controls.
  6. Evidence production model.
  7. Open POA&M items and remediation dates.
  8. Risks requested for acceptance.
  9. Continuous monitoring commitment.
  10. Significant-change and incident-reporting commitments.

Readiness Verdict

Use this verdict language internally until the package is assessed.

VerdictMeaning
Documentation ReadyThe package is ready for sponsor, 3PAO, or AO review, but implementation evidence may still be partial.
Execution ReadyControls are implemented and evidence is generated by normal operations.
Assessment ReadyDocumentation, implementation, evidence, and POA&M are ready for formal 3PAO assessment.
Authorization Decision ReadyAssessment results, POA&M, and residual risk are ready for AO decision.

Non-Negotiable Honesty Rule

Do not state that the system is FedRAMP compliant, FedRAMP authorized, or ATO approved from these template documents. State that the package maps to FedRAMP and NIST 800-53, that it is preparing for a target baseline, and that the final decision belongs to the agency Authorizing Official.

Use this checklist to prove the templates package covers every NIST SP 800-53 family at a documentation level. Not every family is implemented by application code, but every family needs an ownership, inheritance, applicability, or not-applicable decision.

Family Coverage

FamilyDocumentation NeededPrimary Local SourceTemplate Status
ACAccess policy, role matrix, access review, privileged access, remote access, separation of duties.09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdxDraft
ATAwareness and training policy, role-based training, annual acknowledgement.13-policy-library.mdx, 19-record-template-library.mdxDraft
AUAudit policy, auditable events, schema, retention, review, alerting, integrity protection.09-access-audit-and-data-protection-plan.mdx, 15-evidence-automation-map.mdxDraft
CAAssessment plan inputs, ConMon process, POA&M, authorization strategy.01-ato-path-and-assumptions.mdx, 05-evidence-and-conmon-plan.mdxDraft
CMBaseline, inventory, change control, drift detection, emergency changes.08-secure-sdlc-and-supply-chain-plan.mdx, 14-operational-procedure-library.mdxDraft
CPContingency plan, backup, restore, RTO, RPO, exercises.07-incident-contingency-and-dr-plan.mdxDraft
IAIdentity proofing where needed, MFA, account lifecycle, service accounts, credential management.09-access-audit-and-data-protection-plan.mdxDraft
IRIncident response plan, severity, roles, reporting, exercises, after-action review.07-incident-contingency-and-dr-plan.mdx, 19-record-template-library.mdxDraft
MAMaintenance policy, maintenance windows, remote maintenance, tool approval.13-policy-library.mdx, 14-operational-procedure-library.mdxDraft
MPMedia handling, export, backup media, disposal, removable media restrictions.09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdxDraft
PEPhysical and environmental inheritance from cloud or facility provider.02-fips-199-and-boundary.mdx, 12-official-fedramp-package-map.mdxDraft
PLSSP ownership, rules of behavior, architecture, security planning.03-system-security-plan-working-outline.mdx, 13-policy-library.mdxDraft
PMProgram governance, inventory ownership, POA&M governance, risk strategy.01-ato-path-and-assumptions.mdx, 06-poam-and-risk-register.mdxDraft
PSPersonnel screening, joiner-mover-leaver, termination access removal.13-policy-library.mdx, 14-operational-procedure-library.mdxDraft
PTPII authority, minimization, consent, retention, deletion, privacy review.09-access-audit-and-data-protection-plan.mdxDraft
RARisk assessment, vulnerability scanning, remediation windows, acceptance.06-poam-and-risk-register.mdx, 15-evidence-automation-map.mdxDraft
SASecure SDLC, supplier review, test requirements, development standards.08-secure-sdlc-and-supply-chain-plan.mdxDraft
SCBoundary protection, encryption, key management, network segmentation.09-access-audit-and-data-protection-plan.mdx, 10-ato-tooling-overview.mdxDraft
SIFlaw remediation, monitoring, malicious code protection, integrity, validation.08-secure-sdlc-and-supply-chain-plan.mdx, 15-evidence-automation-map.mdxDraft
SRSupplier review, SBOM, provenance, artifact signing, dependency governance.08-secure-sdlc-and-supply-chain-plan.mdx, 15-evidence-automation-map.mdxDraft

Applicability Decisions

Decision TypeRequired WhenEvidence
Implementeddmwd.io owns and operates the control.Implementation statement and repeatable evidence.
Shareddmwd.io and a provider both operate part of the control.Shared responsibility statement and provider evidence.
InheritedProvider fully operates the control.Provider authorization package or responsibility matrix.
Not ApplicableThe control does not apply to the boundary or system model.Rationale accepted by Security and AO or sponsor.
PlannedThe control is required but not implemented yet.POA&M item with owner and date.

Coverage Audit

  • Every family has a policy decision.
  • Every family has at least one evidence source or inheritance statement.
  • Physical and personnel controls have provider or organizational ownership.
  • Privacy controls identify whether PII exists.
  • Supply-chain controls cover both application dependencies and infrastructure artifacts.
  • Significant-change handling ties CA, CM, RA, and SR together.
  • Any not-applicable claim has a written rationale.
  • Any planned claim has a POA&M item.

These record templates make the compliance work repeatable. They are deliberately small so they can become GitHub issue templates, change records, ConMon checklist items, or OSCAL-backed evidence records later.

Monthly ConMon Record

FieldValue
Reporting month[FILL IN]
System and environment[FILL IN]
Inventory version[FILL IN]
Vulnerability scans attached[FILL IN]
POA&M status[FILL IN: open, new, closed, overdue]
Significant changes[FILL IN]
Access review status[FILL IN]
Backup and restore status[FILL IN]
Incidents or alerts[FILL IN]
Security sign-off[FILL IN]
Platform sign-off[FILL IN]

Access Review Record

FieldValue
Review scope[FILL IN: GitHub, IdP, Kubernetes, database, secret manager]
Review period[FILL IN]
Export location[FILL IN]
Reviewer[FILL IN]
Removed access[FILL IN]
Exceptions[FILL IN]
Break-glass use reviewed[FILL IN]
Approval[FILL IN]

POA&M Item Record

FieldValue
POA&M ID[FILL IN]
Source[FILL IN]
Control[FILL IN]
Weakness[FILL IN]
Severity[FILL IN]
Owner[FILL IN]
Milestones[FILL IN]
Due date[FILL IN]
Status[FILL IN]
Closure evidence[FILL IN]

Significant Change Record

FieldValue
Change ID[FILL IN]
Change summary[FILL IN]
Reason[FILL IN]
Affected services[FILL IN]
Affected controls[FILL IN]
Customer impact[FILL IN]
Security impact analysis[FILL IN]
Privacy impact analysis[FILL IN]
Validation plan[FILL IN]
Rollback plan[FILL IN]
AO notification decision[FILL IN]
Approver[FILL IN]

Incident Record

FieldValue
Incident ID[FILL IN]
Severity[FILL IN]
Detection source[FILL IN]
Start time[FILL IN]
Incident commander[FILL IN]
Affected systems[FILL IN]
Data impact[FILL IN]
Containment actions[FILL IN]
Notifications[FILL IN]
Recovery time[FILL IN]
Evidence location[FILL IN]
POA&M follow-ups[FILL IN]

Backup Restore Test Record

FieldValue
Test ID[FILL IN]
System[FILL IN]
Backup source[FILL IN]
Restore target[FILL IN]
RTO target[FILL IN]
RTO actual[FILL IN]
RPO target[FILL IN]
RPO actual[FILL IN]
Validation performed[FILL IN]
Issues found[FILL IN]
Evidence location[FILL IN]

Supplier Review Record

FieldValue
Supplier[FILL IN]
Service[FILL IN]
Boundary relationship[FILL IN: inherited, shared, external, subprocessor]
Data handled[FILL IN]
Authorization evidence[FILL IN]
Security documentation[FILL IN]
Privacy documentation[FILL IN]
Exit plan[FILL IN]
Renewal date[FILL IN]
Risk decision[FILL IN]

Risk Acceptance Record

FieldValue
Risk ID[FILL IN]
Related POA&M ID[FILL IN]
Control[FILL IN]
Risk owner[FILL IN]
Compensating controls[FILL IN]
Acceptance period[FILL IN]
Expiration date[FILL IN]
AO decision[FILL IN]
Review trigger[FILL IN]