Evidence & Evidence Quality

FedRAMP 20x expects evidence that a Key Security Indicator is actually met — preferably machine-readable, dated, and replayable. scm.cc does not invent official evidence checklists. The strong/weak pairs below are educational illustrations labeled as such.

Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.

Technical detail

In this product, derived evidence envelopes carry a verdict (met, gap, or manual), an artifact hash, and a customer-side pointer. A control with no covering evidence is unknown, never met. Conflicting evidence is fail-closed. Freshness is the collection timestamp, not a claim that the live system is unchanged after that instant.

How to implement

Use the Evidence Quality Checker when it ships. Until then, map each KSI statement to a stored artifact with a date. Do not upload customer CUI to scm.cc as a substitute for a derived envelope.

Evidence expectations

Strong evidence names the resource, the window, the collector or reviewer, and can be replayed. Weak evidence is undated, unscoped, or a policy statement with no artifact. Automated methods beat a one-time screenshot when the KSI calls for persistent validation.

Strong evidence

- KSI-CED (Cybersecurity Education): Dated training completion records with role, curriculum version, and a review of effectiveness for the current window. - KSI-CMT (Change Management): Change tickets that list the resource, the intended state, the reviewer, and a post-change config snapshot hash. - KSI-CNA (Cloud Native Architecture): Automated intended-state checks on machine resources with a fail-closed record when drift is found. - KSI-IAM (Identity and Access Management): IdP logs showing MFA, least-privilege role assignment, and a recent access review with named reviewers. - KSI-INR (Incident Response): An incident record with detection time, containment steps, and a dated after-action that names residual risk. - KSI-MLA (Monitoring, Logging, and Auditing): Central log pipeline with retention, integrity controls, and a query that an operator can replay for the window. - KSI-PIY (Policy and Inventory): Inventory of information resources with owner, data type, and last-seen timestamp from the collector. - KSI-RPL (Recovery Planning): Restore test results with RPO/RTO measured against the current backup set. - KSI-SCR (Supply Chain Risk): SBOM plus a dated review of dependency advisories that maps to running versions. - KSI-SVC (Service Configuration): Automated residual-risk review after a change, plus a customer-data deletion receipt when requested.

Weak evidence

- KSI-CED (Cybersecurity Education): A slide deck titled 'security awareness' with no attendees, date, or role mapping. - KSI-CMT (Change Management): A chat message saying 'we patched prod' with no ticket, no resource id, and no timestamp. - KSI-CNA (Cloud Native Architecture): A screenshot of a console taken once at onboarding, never refreshed. - KSI-IAM (Identity and Access Management): A policy PDF that says 'we use MFA' with no live identity-store export. - KSI-INR (Incident Response): A runbook that has never been used and has no last-tested date. - KSI-MLA (Monitoring, Logging, and Auditing): Local syslog files on a laptop that is not in the system boundary. - KSI-PIY (Policy and Inventory): A spreadsheet last edited two years ago with unnamed 'servers'. - KSI-RPL (Recovery Planning): A vendor brochure claiming backups exist. - KSI-SCR (Supply Chain Risk): A logo list of vendors with no versions or last-reviewed date. - KSI-SVC (Service Configuration): A statement that 'we delete data when asked' with no ticket or timestamp.

Common mistakes

- Calling a policy PDF 'implemented' with no runtime artifact. - Reusing a screenshot from a previous authorization window. - Treating unknown coverage as met.

Strong vs weak (illustrative, per KSI family)

These pairs are scm.cc-authored teaching examples, not official FedRAMP checklists.

FamilyStrong (illustration)Weak (illustration)
KSI-CEDDated training completion records with role, curriculum version, and a review of effectiveness for the current window.A slide deck titled 'security awareness' with no attendees, date, or role mapping.
KSI-CMTChange tickets that list the resource, the intended state, the reviewer, and a post-change config snapshot hash.A chat message saying 'we patched prod' with no ticket, no resource id, and no timestamp.
KSI-CNAAutomated intended-state checks on machine resources with a fail-closed record when drift is found.A screenshot of a console taken once at onboarding, never refreshed.
KSI-IAMIdP logs showing MFA, least-privilege role assignment, and a recent access review with named reviewers.A policy PDF that says 'we use MFA' with no live identity-store export.
KSI-INRAn incident record with detection time, containment steps, and a dated after-action that names residual risk.A runbook that has never been used and has no last-tested date.
KSI-MLACentral log pipeline with retention, integrity controls, and a query that an operator can replay for the window.Local syslog files on a laptop that is not in the system boundary.
KSI-PIYInventory of information resources with owner, data type, and last-seen timestamp from the collector.A spreadsheet last edited two years ago with unnamed 'servers'.
KSI-RPLRestore test results with RPO/RTO measured against the current backup set.A vendor brochure claiming backups exist.
KSI-SCRSBOM plus a dated review of dependency advisories that maps to running versions.A logo list of vendors with no versions or last-reviewed date.
KSI-SVCAutomated residual-risk review after a change, plus a customer-data deletion receipt when requested.A statement that 'we delete data when asked' with no ticket or timestamp.

Try the Evidence Quality Checker (in progress).

Questions teams ask

Are the strong/weak examples official FedRAMP rules?
No. They are scm.cc-authored illustrations. The official requirement is the KSI statement on FedRAMP.gov.
Does a green cell mean the control is effective?
No. A met cell means covering derived evidence existed in the window. It is not an assessor verdict.

Related hub pages

Primary sources

Last verified 2026-09-27. FedRAMP.gov is authoritative.

Explore the knowledge hub