FedRAMP 20x Key Security Indicators (KSIs)
All 46 indicators in 10 families from the FedRAMP Consolidated Rules for 2026, with the official statement and related controls for each.
Source: https://fedramp.gov/2026/reference/20x/c/key-security-indicators/. Pinned 2026-09-27 (catalog fedramp-20x-ksi/official-1.0.0-cr26). This page shows the list as pinned on that date. A weekly automated check flags any difference from the official page.
Cybersecurity Education KSI-CED
- KSI-CED-RAT - Reviewing All Training
Change Management KSI-CMT
- KSI-CMT-LMC - Logging Changes
- KSI-CMT-RMV - Redeploying vs Modifying
- KSI-CMT-RVP - Reviewing Change Procedures
- KSI-CMT-VTD - Validating Throughout Deployment
Cloud Native Architecture KSI-CNA
- KSI-CNA-DFP - Defining Functionality and Privileges
- KSI-CNA-EIS - Enforcing Intended State
- KSI-CNA-IBP - Implementing Best Practices
- KSI-CNA-MAT - Minimizing Attack Surface
- KSI-CNA-OFA - Optimizing for Availability
- KSI-CNA-RNT - Restricting Network Traffic
- KSI-CNA-RVP - Reviewing Protections
- KSI-CNA-ULN - Using Logical Networking
Identity and Access Management KSI-IAM
- KSI-IAM-AAM - Automating Account Management
- KSI-IAM-APM - Adopting Passwordless Methods
- KSI-IAM-ELP - Ensuring Least Privilege
- KSI-IAM-JIT - Authorizing Just-in-Time
- KSI-IAM-SNU - Securing Non-User Authentication
- KSI-IAM-SUS - Responding to Suspicious Activity
Incident Response KSI-INR
- KSI-INR-AAR - Generating After Action Reports
- KSI-INR-RIR - Reviewing Incident Response Procedures
- KSI-INR-RPI - Reviewing Past Incidents
Monitoring, Logging, and Auditing KSI-MLA
- KSI-MLA-ALA - Authorizing Log Access
- KSI-MLA-EVC - Evaluating Configurations
- KSI-MLA-LET - Logging Event Types
- KSI-MLA-OSM - Operating SIEM Capability
- KSI-MLA-RVL - Reviewing Logs
Policy and Inventory KSI-PIY
- KSI-PIY-GIV - Generating Inventories
- KSI-PIY-RES - Reviewing Executive Support
- KSI-PIY-RIS - Reviewing Investments in Security
- KSI-PIY-RSD - Reviewing Security in the SDLC
- KSI-PIY-RVD - Reviewing Vulnerability Disclosures
Recovery Planning KSI-RPL
- KSI-RPL-ABO - Aligning Backups with Objectives
- KSI-RPL-ARP - Aligning Recovery Plan
- KSI-RPL-RRO - Reviewing Recovery Objectives
- KSI-RPL-TRC - Testing Recovery Capabilities
Supply Chain Risk KSI-SCR
- KSI-SCR-MIT - Mitigating Supply Chain Risk
- KSI-SCR-MON - Monitoring Supply Chain Risk
Service Configuration KSI-SVC
- KSI-SVC-ACM - Automating Configuration Management
- KSI-SVC-ASM - Automating Secret Management
- KSI-SVC-EIS - Evaluating and Improving Security
- KSI-SVC-PRR - Preventing Residual Risk
- KSI-SVC-RUD - Removing Unwanted Data
- KSI-SVC-SIN - Securing Information
- KSI-SVC-VCM - Validating Communications
- KSI-SVC-VRI - Validating Resource Integrity