Evidence & Evidence Quality
FedRAMP 20x expects evidence that a Key Security Indicator is actually met — preferably machine-readable, dated, and replayable. scm.cc does not invent official evidence checklists. The strong/weak pairs below are educational illustrations labeled as such.
Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.
Technical detail
In this product, derived evidence envelopes carry a verdict (met, gap, or manual), an artifact hash, and a customer-side pointer. A control with no covering evidence is unknown, never met. Conflicting evidence is fail-closed. Freshness is the collection timestamp, not a claim that the live system is unchanged after that instant.
How to implement
Use the Evidence Quality Checker when it ships. Until then, map each KSI statement to a stored artifact with a date. Do not upload customer CUI to scm.cc as a substitute for a derived envelope.
Evidence expectations
Strong evidence names the resource, the window, the collector or reviewer, and can be replayed. Weak evidence is undated, unscoped, or a policy statement with no artifact. Automated methods beat a one-time screenshot when the KSI calls for persistent validation.
Strong evidence
- KSI-CED (Cybersecurity Education): Dated training completion records with role, curriculum version, and a review of effectiveness for the current window. - KSI-CMT (Change Management): Change tickets that list the resource, the intended state, the reviewer, and a post-change config snapshot hash. - KSI-CNA (Cloud Native Architecture): Automated intended-state checks on machine resources with a fail-closed record when drift is found. - KSI-IAM (Identity and Access Management): IdP logs showing MFA, least-privilege role assignment, and a recent access review with named reviewers. - KSI-INR (Incident Response): An incident record with detection time, containment steps, and a dated after-action that names residual risk. - KSI-MLA (Monitoring, Logging, and Auditing): Central log pipeline with retention, integrity controls, and a query that an operator can replay for the window. - KSI-PIY (Policy and Inventory): Inventory of information resources with owner, data type, and last-seen timestamp from the collector. - KSI-RPL (Recovery Planning): Restore test results with RPO/RTO measured against the current backup set. - KSI-SCR (Supply Chain Risk): SBOM plus a dated review of dependency advisories that maps to running versions. - KSI-SVC (Service Configuration): Automated residual-risk review after a change, plus a customer-data deletion receipt when requested.
Weak evidence
- KSI-CED (Cybersecurity Education): A slide deck titled 'security awareness' with no attendees, date, or role mapping. - KSI-CMT (Change Management): A chat message saying 'we patched prod' with no ticket, no resource id, and no timestamp. - KSI-CNA (Cloud Native Architecture): A screenshot of a console taken once at onboarding, never refreshed. - KSI-IAM (Identity and Access Management): A policy PDF that says 'we use MFA' with no live identity-store export. - KSI-INR (Incident Response): A runbook that has never been used and has no last-tested date. - KSI-MLA (Monitoring, Logging, and Auditing): Local syslog files on a laptop that is not in the system boundary. - KSI-PIY (Policy and Inventory): A spreadsheet last edited two years ago with unnamed 'servers'. - KSI-RPL (Recovery Planning): A vendor brochure claiming backups exist. - KSI-SCR (Supply Chain Risk): A logo list of vendors with no versions or last-reviewed date. - KSI-SVC (Service Configuration): A statement that 'we delete data when asked' with no ticket or timestamp.
Common mistakes
- Calling a policy PDF 'implemented' with no runtime artifact. - Reusing a screenshot from a previous authorization window. - Treating unknown coverage as met.
Strong vs weak (illustrative, per KSI family)
These pairs are scm.cc-authored teaching examples, not official FedRAMP checklists.
| Family | Strong (illustration) | Weak (illustration) |
|---|---|---|
| KSI-CED | Dated training completion records with role, curriculum version, and a review of effectiveness for the current window. | A slide deck titled 'security awareness' with no attendees, date, or role mapping. |
| KSI-CMT | Change tickets that list the resource, the intended state, the reviewer, and a post-change config snapshot hash. | A chat message saying 'we patched prod' with no ticket, no resource id, and no timestamp. |
| KSI-CNA | Automated intended-state checks on machine resources with a fail-closed record when drift is found. | A screenshot of a console taken once at onboarding, never refreshed. |
| KSI-IAM | IdP logs showing MFA, least-privilege role assignment, and a recent access review with named reviewers. | A policy PDF that says 'we use MFA' with no live identity-store export. |
| KSI-INR | An incident record with detection time, containment steps, and a dated after-action that names residual risk. | A runbook that has never been used and has no last-tested date. |
| KSI-MLA | Central log pipeline with retention, integrity controls, and a query that an operator can replay for the window. | Local syslog files on a laptop that is not in the system boundary. |
| KSI-PIY | Inventory of information resources with owner, data type, and last-seen timestamp from the collector. | A spreadsheet last edited two years ago with unnamed 'servers'. |
| KSI-RPL | Restore test results with RPO/RTO measured against the current backup set. | A vendor brochure claiming backups exist. |
| KSI-SCR | SBOM plus a dated review of dependency advisories that maps to running versions. | A logo list of vendors with no versions or last-reviewed date. |
| KSI-SVC | Automated residual-risk review after a change, plus a customer-data deletion receipt when requested. | A statement that 'we delete data when asked' with no ticket or timestamp. |
Try the Evidence Quality Checker (in progress).
Questions teams ask
- Are the strong/weak examples official FedRAMP rules?
- No. They are scm.cc-authored illustrations. The official requirement is the KSI statement on FedRAMP.gov.
- Does a green cell mean the control is effective?
- No. A met cell means covering derived evidence existed in the window. It is not an assessor verdict.
Related hub pages
Primary sources
- FedRAMP 20x Key Security Indicators (CR26) (retrieved 2026-09-27)
- Security Decision Record (replaces the SSP) (retrieved 2026-09-27)
- Collaborative Continuous Monitoring (CCM / Ongoing Certification Report) (retrieved 2026-09-27)
Last verified 2026-09-27. FedRAMP.gov is authoritative.