KSI-IAM-JIT — Authorizing Just-in-Time

Official CR26 Key Security Indicator in the Identity and Access Management family (KSI-IAM). The statement below is verbatim from the catalog.

Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.

Official requirement

A least-privileged, role and attribute-based, and just-in-time security authorization model is used and persistently reviewed for all user and non-user accounts and services.

Assessment considerations

The official reference cites no related SP 800-53 controls for this indicator.

Static HTML reference: scm.cc/ksi/ksi-iam-jit/. Interactive view: KSI Explorer (in progress).

Related hub pages

Primary sources

Last verified 2026-09-27. FedRAMP.gov is authoritative.

Explore the knowledge hub