scm.cc / FedRAMP 20x KSIs

KSI-PIY-RSD - Policy and Inventory

Reviewing Security in the SDLC

Official statement

The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.

The official reference cites no related SP 800-53 controls for this indicator.

Other Policy and Inventory indicators

Source: https://fedramp.gov/2026/reference/20x/c/key-security-indicators/. Pinned 2026-09-27 (catalog fedramp-20x-ksi/official-1.0.0-cr26). This page shows the list as pinned on that date. A weekly automated check flags any difference from the official page.

All 20x Key Security Indicators