Cloud Shared Responsibility Mapper
Framework

FedRAMP Moderate: the clauses behind the split

FedRAMP Moderate, quoted at its anchors for external services (SA-9) and information exchange (CA-3) and the controls a cloud estate is most often asked about. The FedRAMP customer responsibility matrix template is named, not quoted.

Shown when ticked. The framework on the compliance library.

Control areas it anchors

4
AreaClause
Identity and accessFedRAMP AC-2
Encryption and keysFedRAMP SC-12
Network securityFedRAMP SC-7
Supplier and subserviceFedRAMP SA-9 ยท FedRAMP CA-3

Every clause cited, quoted

5 of the 323 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

FedRAMP AC-2 Account Management

Manage accounts; review at least monthly for privileged, every six months for non-privileged (FedRAMP); notify within FedRAMP-defined timeframes on changes.

What an assessor asks to see:
  • Control implementation statement for AC-2 citing the system mission and inheritance from common controls
  • Joiner mover leaver workflow evidence integrated with HR
  • Access control policy approved by the information security officer
  • Role-based access matrix mapped to job functions and data classifications
  • Account provisioning and deprovisioning workflow tickets with manager approvals
  • Quarterly privileged access review attestations
Where it usually falls short:
  • Stale accounts retained for terminated personnel beyond the 24 hour SLA
  • Privileged accounts shared across administrators without individual accountability
  • Access reviews performed but exceptions never remediated
  • Role definitions drift from documented matrix without change control
Source: FedRAMP Moderate
FedRAMP CA-3 Information Exchange

Approve and manage exchange of information with external systems using ISA, MOU, contract; review annually.

What an assessor asks to see:
  • Control implementation statement for CA-3 citing the system mission and inheritance from common controls
  • System security plan covering the authorization boundary
  • Control assessment report with tester names and dates
  • Plan of action and milestones tracking open findings
  • Authorization to operate memorandum signed by the authorizing official
Where it usually falls short:
  • POAM items past due without justification or risk acceptance
  • Continuous monitoring metrics collected but not reported to leadership
  • Assessment scope omits inherited cloud provider controls
Source: FedRAMP Moderate
FedRAMP SA-9 External System Services

Require providers of external system services to comply with security/privacy requirements; document oversight roles.

What an assessor asks to see:
  • Control implementation statement for SA-9 citing the system mission and inheritance from common controls
  • Vendor security questionnaires and SOC reports retained
  • Software bill of materials for in scope products
  • Acquisition policy with security clauses for contracts
  • Secure software development lifecycle procedures
Where it usually falls short:
  • Vendor SOC reports collected but exceptions not analysed
  • Code scan findings closed without verification of fix
  • Security requirements absent from procurement templates for low value buys
Source: FedRAMP Moderate
FedRAMP SC-7 Boundary Protection

Monitor/control communications at external boundary and key internal boundaries; implement subnetworks for publicly accessible components.

What an assessor asks to see:
  • Control implementation statement for SC-7 citing the system mission and inheritance from common controls
  • Network segmentation diagrams with VLAN and zone mapping
  • Denial of service protection configuration and capacity test results
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
Where it usually falls short:
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
Source: FedRAMP Moderate
FedRAMP SC-12 Cryptographic Key Establishment and Management

Establish and manage cryptographic keys per FedRAMP requirements (FIPS-validated, key escrow/recovery as appropriate).

What an assessor asks to see:
  • Control implementation statement for SC-12 citing the system mission and inheritance from common controls
  • Boundary protection architecture with firewall and proxy rule documentation
  • Cryptographic standards specifying approved algorithms and key lengths
  • Key management procedures including rotation and escrow
  • TLS configuration scan results across in scope endpoints
Where it usually falls short:
  • Firewall rule base contains stale allow any entries
  • Internal traffic between services unencrypted within trusted zones
  • Legacy TLS versions remain enabled on external services
Source: FedRAMP Moderate