FedRAMP Moderate: the clauses behind the split
FedRAMP Moderate, quoted at its anchors for external services (SA-9) and information exchange (CA-3) and the controls a cloud estate is most often asked about. The FedRAMP customer responsibility matrix template is named, not quoted.
Shown when ticked. The framework on the compliance library.
Control areas it anchors
4| Area | Clause |
|---|---|
| Identity and access | FedRAMP AC-2 |
| Encryption and keys | FedRAMP SC-12 |
| Network security | FedRAMP SC-7 |
| Supplier and subservice | FedRAMP SA-9 ยท FedRAMP CA-3 |
Every clause cited, quoted
5 of the 323 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
FedRAMP AC-2 Account ManagementManage accounts; review at least monthly for privileged, every six months for non-privileged (FedRAMP); notify within FedRAMP-defined timeframes on changes.
- Control implementation statement for AC-2 citing the system mission and inheritance from common controls
- Joiner mover leaver workflow evidence integrated with HR
- Access control policy approved by the information security officer
- Role-based access matrix mapped to job functions and data classifications
- Account provisioning and deprovisioning workflow tickets with manager approvals
- Quarterly privileged access review attestations
- Stale accounts retained for terminated personnel beyond the 24 hour SLA
- Privileged accounts shared across administrators without individual accountability
- Access reviews performed but exceptions never remediated
- Role definitions drift from documented matrix without change control
FedRAMP CA-3 Information ExchangeApprove and manage exchange of information with external systems using ISA, MOU, contract; review annually.
- Control implementation statement for CA-3 citing the system mission and inheritance from common controls
- System security plan covering the authorization boundary
- Control assessment report with tester names and dates
- Plan of action and milestones tracking open findings
- Authorization to operate memorandum signed by the authorizing official
- POAM items past due without justification or risk acceptance
- Continuous monitoring metrics collected but not reported to leadership
- Assessment scope omits inherited cloud provider controls
FedRAMP SA-9 External System ServicesRequire providers of external system services to comply with security/privacy requirements; document oversight roles.
- Control implementation statement for SA-9 citing the system mission and inheritance from common controls
- Vendor security questionnaires and SOC reports retained
- Software bill of materials for in scope products
- Acquisition policy with security clauses for contracts
- Secure software development lifecycle procedures
- Vendor SOC reports collected but exceptions not analysed
- Code scan findings closed without verification of fix
- Security requirements absent from procurement templates for low value buys
FedRAMP SC-7 Boundary ProtectionMonitor/control communications at external boundary and key internal boundaries; implement subnetworks for publicly accessible components.
- Control implementation statement for SC-7 citing the system mission and inheritance from common controls
- Network segmentation diagrams with VLAN and zone mapping
- Denial of service protection configuration and capacity test results
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services
FedRAMP SC-12 Cryptographic Key Establishment and ManagementEstablish and manage cryptographic keys per FedRAMP requirements (FIPS-validated, key escrow/recovery as appropriate).
- Control implementation statement for SC-12 citing the system mission and inheritance from common controls
- Boundary protection architecture with firewall and proxy rule documentation
- Cryptographic standards specifying approved algorithms and key lengths
- Key management procedures including rotation and escrow
- TLS configuration scan results across in scope endpoints
- Firewall rule base contains stale allow any entries
- Internal traffic between services unencrypted within trusted zones
- Legacy TLS versions remain enabled on external services