Skip to main content
WhyHow It WorksFeaturesPricingBlog
Sign inRequest demo

FedRAMP 20x for cloud service providers

Know what is required. Build it. Prove it.

Search every KSI and the 148 rules addressed to providers. See the requirement, implementation guidance, and evidence context without sorting through obligations owned by agencies, assessors, or FedRAMP.

Based on FedRAMP/rules 2026.06.04.01-preview, updated 2026-06-04

CSP implementation explorer

Showing 46 of 254 CSP resources

KSICED
KSI-CED-RAT

Reviewing All Training

All service classesOfficial source
KSICMT
KSI-CMT-LMC

Logging Changes

All service classesOfficial source
KSICMT
KSI-CMT-RMV

Redeploying vs Modifying

All service classesOfficial source
KSICMT
KSI-CMT-RVP

Reviewing Change Procedures

All service classesOfficial source
KSICMT
KSI-CMT-VTD

Validating Throughout Deployment

All service classesOfficial source
KSICNA
KSI-CNA-DFP

Defining Functionality and Privileges

All service classesOfficial source
KSICNA
KSI-CNA-EIS

Enforcing Intended State

Classes B, COfficial source
KSICNA
KSI-CNA-IBP

Implementing Best Practices

All service classesOfficial source
KSICNA
KSI-CNA-MAT

Minimizing Attack Surface

All service classesOfficial source
KSICNA
KSI-CNA-OFA

Optimizing for Availability

All service classesOfficial source
KSICNA
KSI-CNA-RNT

Restricting Network Traffic

All service classesOfficial source
KSICNA
KSI-CNA-RVP

Reviewing Protections

All service classesOfficial source
KSICNA
KSI-CNA-ULN

Using Logical Networking

All service classesOfficial source
KSIIAM
KSI-IAM-AAM

Automating Account Management

All service classesOfficial source
KSIIAM
KSI-IAM-APM

Adopting Passwordless Methods

All service classesOfficial source
KSIIAM
KSI-IAM-ELP

Ensuring Least Privilege

All service classesOfficial source
KSIIAM
KSI-IAM-JIT

Authorizing Just-in-Time

All service classesOfficial source
KSIIAM
KSI-IAM-SNU

Securing Non-User Authentication

All service classesOfficial source
KSIIAM
KSI-IAM-SUS

Responding to Suspicious Activity

All service classesOfficial source
KSIINR
KSI-INR-AAR

Generating After Action Reports

All service classesOfficial source
KSIINR
KSI-INR-RIR

Reviewing Incident Response Procedures

All service classesOfficial source
KSIINR
KSI-INR-RPI

Reviewing Past Incidents

All service classesOfficial source
KSIMLA
KSI-MLA-ALA

Authorizing Log Access

Classes B, COfficial source
KSIMLA
KSI-MLA-EVC

Evaluating Configurations

All service classesImplementation guidance Automated check
KSIMLA
KSI-MLA-LET

Logging Event Types

All service classesOfficial source
KSIMLA
KSI-MLA-OSM

Operating SIEM Capability

All service classesOfficial source
KSIMLA
KSI-MLA-RVL

Reviewing Logs

All service classesOfficial source
KSIPIY
KSI-PIY-GIV

Generating Inventories

All service classesOfficial source
KSIPIY
KSI-PIY-RES

Reviewing Executive Support

All service classesOfficial source
KSIPIY
KSI-PIY-RIS

Reviewing Investments in Security

All service classesOfficial source
KSIPIY
KSI-PIY-RSD

Reviewing Security in the SDLC

All service classesOfficial source
KSIPIY
KSI-PIY-RVD

Reviewing Vulnerability Disclosures

All service classesOfficial source
KSIRPL
KSI-RPL-ABO

Aligning Backups with Objectives

All service classesOfficial source
KSIRPL
KSI-RPL-ARP

Aligning Recovery Plan

All service classesOfficial source
KSIRPL
KSI-RPL-RRO

Reviewing Recovery Objectives

All service classesOfficial source
KSIRPL
KSI-RPL-TRC

Testing Recovery Capabilities

All service classesOfficial source
KSISCR
KSI-SCR-MIT

Mitigating Supply Chain Risk

All service classesOfficial source
KSISCR
KSI-SCR-MON

Monitoring Supply Chain Risk

All service classesOfficial source
KSISVC
KSI-SVC-ACM

Automating Configuration Management

All service classesOfficial source
KSISVC
KSI-SVC-ASM

Automating Secret Management

All service classesOfficial source
KSISVC
KSI-SVC-EIS

Evaluating and Improving Security

All service classesOfficial source
KSISVC
KSI-SVC-PRR

Preventing Residual Risk

Classes B, COfficial source
KSISVC
KSI-SVC-RUD

Removing Unwanted Data

Classes B, COfficial source
KSISVC
KSI-SVC-SNT

Securing Network Traffic

All service classesOfficial source
KSISVC
KSI-SVC-VCM

Validating Communications

Classes B, COfficial source
KSISVC
KSI-SVC-VRI

Validating Resource Integrity

All service classesOfficial source