Inside the SDR example
FedRAMP describes the Security Decision Record as a persistently maintained record of the security decisions made across a cloud service offering's lifecycle. This example illustrates that model through 158 synthetic FedRAMP rule records and 46 synthetic Key Security Indicator records.
The rule entries demonstrate statuses, implementation statements, validation statements, and places where assessment or clarification information can be carried. The KSI entries add measures, test references, evidence descriptions, current status, and metrics. The included metrics window contains 52 example evaluation points from 2025-08-04 through 2026-07-27, plus 30-day and past-year summaries. The HTML intentionally renders a very large JSON document so teams can examine navigation, summarization, accessibility, and parity challenges.
What to learn from the pair
Use this example to study relationships, not to copy conclusions. Follow a rule identifier from its status to its implementation and validation text. Then examine a KSI from its measures and evidence through test references and historical measurements. That flow can inform data models, evidence pipelines, reviewer views, change detection, and quality checks.
A useful implementation should make incomplete, stale, conflicting, or unsupported statements easy to find. It should distinguish provider verification, provider validation, independent review, and attached artifacts instead of collapsing them into a generic compliant result. Current Security Decision Record rules and schemas remain the source of truth for required fields and applicability.
Synthetic example and current status
These files were generated on 2026-07-27. Their rule statuses, KSI results, evidence, metrics, people, systems, assessments, and security narratives are fictional. Some source text names a demo organization other than Boundera; that is part of the synthetic dataset, not a Boundera claim. Use the official FedRAMP Marketplace record for current status.