Skip to main content
Pricing
Sign inRequest demo

FedRAMP 20x Security Decision Record (SDR) Example

Explore a substantial SDR example containing FedRAMP rule records, KSI summaries, validation statements, evidence references, tests, and historical metrics.

0 downloads|ZIP (HTML + JSON)|89.1 KB

What's inside

  • Map implementation and validation statements to rules and KSIs
  • Understand how KSI evidence, tests, and metrics can be represented
  • Compare a large JSON record with its readable HTML output
  • Prototype SDR search, filtering, and generation workflows

Best fit

  • Security and compliance engineers
  • KSI evidence owners
  • Assessors and technical reviewers

Related topics

#Continuous Validation#FedRAMP 20x#Historical Metrics#HTML Example#JSON Example#Key Security Indicators (KSI)#Security Decision Record (SDR)#Security Decisions

Unlock this resource

Enter your work email to download FedRAMP 20x Security Decision Record (SDR) Example.

Inside the SDR example

FedRAMP describes the Security Decision Record as a persistently maintained record of the security decisions made across a cloud service offering's lifecycle. This example illustrates that model through 158 synthetic FedRAMP rule records and 46 synthetic Key Security Indicator records.

The rule entries demonstrate statuses, implementation statements, validation statements, and places where assessment or clarification information can be carried. The KSI entries add measures, test references, evidence descriptions, current status, and metrics. The included metrics window contains 52 example evaluation points from 2025-08-04 through 2026-07-27, plus 30-day and past-year summaries. The HTML intentionally renders a very large JSON document so teams can examine navigation, summarization, accessibility, and parity challenges.

What to learn from the pair

Use this example to study relationships, not to copy conclusions. Follow a rule identifier from its status to its implementation and validation text. Then examine a KSI from its measures and evidence through test references and historical measurements. That flow can inform data models, evidence pipelines, reviewer views, change detection, and quality checks.

A useful implementation should make incomplete, stale, conflicting, or unsupported statements easy to find. It should distinguish provider verification, provider validation, independent review, and attached artifacts instead of collapsing them into a generic compliant result. Current Security Decision Record rules and schemas remain the source of truth for required fields and applicability.

Synthetic example and current status

These files were generated on 2026-07-27. Their rule statuses, KSI results, evidence, metrics, people, systems, assessments, and security narratives are fictional. Some source text names a demo organization other than Boundera; that is part of the synthetic dataset, not a Boundera claim. Use the official FedRAMP Marketplace record for current status.

Frequently asked questions

Why is the SDR example so large?

It contains 158 rule records, 46 KSI records, and 52 synthetic historical metric points for each applicable example series.

Does a Security Decision Record replace every other package artifact?

No. It records security decisions and related verification, validation, assessment, and artifacts; other package materials still have distinct purposes.

Can these statuses or metrics be reused as evidence?

No. They are synthetic and must not be represented as actual implementation, assessment, or certification results.

Put this resource to work

Turn this resource into a live FedRAMP workflow.

Boundera connects the evidence, gaps, POA&Ms, and continuous monitoring work behind the document.

Request demo

Related resources