KSI-CNA-DFP — Defining Functionality and Privileges
Official CR26 Key Security Indicator in the Cloud Native Architecture family (KSI-CNA). The statement below is verbatim from the catalog.
Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.
Official requirement
The functionality and privileges for infrastructure and services are strictly defined.
Assessment considerations
Official related SP 800-53 controls: CM-02, SI-03.
Static HTML reference: scm.cc/ksi/ksi-cna-dfp/. Interactive view: KSI Explorer (in progress).
Related hub pages
Primary sources
- FedRAMP 20x Key Security Indicators (CR26) (retrieved 2026-09-27)
Last verified 2026-09-27. FedRAMP.gov is authoritative.