FR

CTL · Control Parameters

Control Parameters

FedRAMP-specific parameter values and guidance applied on top of NIST SP 800-53 controls. These set the organization-defined parameters (ODPs) and clarify how the baseline controls apply.

AC

AC Family

4 controls
AC-6(1)
ParameterValue
ac-06.01_odp.02all functions not publicly accessible
ac-06.01_odp.05all security-relevant information not publicly available
AC-6(2)
ParameterValue
ac-06.02_odpall security functions
AC-6(8)
ParameterValue
ac-06.08_odpany software except software explicitly documented
AC-20

Guidance

  • The interrelated controls of AC-20, CA-3, and SA-9 should be differentiated as follows:
  • AC-20 describes system access to and from external systems.
  • CA-3 describes documentation of an agreement between the respective system owners when data is exchanged between the CSO and an external system.
  • SA-9 describes the responsibilities of external system owners. These responsibilities would typically be captured in the agreement required by CA-3.
AU

AU Family

4 controls
AU-6

Guidance

  • This activity is considered vulnerability detection and is subject to the Vulnerability Detection and Response rules.
AU-6(5)

Guidance

  • This activity is considered vulnerability detection and is subject to the Vulnerability Detection and Response rules.
AU-10
ParameterValue
au-10_odpat least actions including the addition, modification, deletion, approval, sending, or receiving of data
AU-12
ParameterValue
au-12_odp.01at least all information system and network components where audit capability is deployed/available
CA

CA Family

4 controls
CA-2
ParameterValue
ca-02_odp.02individuals or roles to include FedRAMP and agency customers
CA-2(3)
ParameterValue
ca-02.03_odp.01any FedRAMP Recognized independent assessment service
CA-7

Guidance

  • Follow the FedRAMP Continuous Collaborative Monitoring, Significant Change Notification, Vulnerability Detection and Response, and Vulnerability Evaluation and Reporting rules.
CA-8

Guidance

  • Penetration testing is part of vulnerability detection and is subject to the Vulnerability Detection and Response rules.
CM

CM Family

6 controls
CM-1

Guidance

  • Follow the Significant Change Notification rules.
CM-8

Guidance

  • Follow the FedRAMP Continuous Collaborative Monitoring, Significant Change Notification, Vulnerability Detection and Response, and Vulnerability Evaluation and Reporting rules.
CM-11
ParameterValue
cm-11_odp.03Continuously (via CM-7 (5))
CM-12

Guidance

  • Follow the FedRAMP Minimum Assessment Scope rules.
CM-12(1)

Guidance

  • Follow the FedRAMP Minimum Assessment Scope rules.
CM-14

Guidance

  • If digital signatures/certificates are unavailable, alternative cryptographic integrity checks (hashes, self-signed certs, etc.) can be utilized.
CP

CP Family

3 controls
CP-2(3)
ParameterValue
cp-02.03_odp.02time period defined in service provider and organization Service Level Agreements
CP-7(1)

Guidance

  • The service provider may determine what is considered a sufficient degree of separation between the primary and alternate processing sites, based on the types of threats that are of concern. For one particular type of threat (i.e., hostile cyber attack), the degree of separation between sites will be less relevant.
CP-10(4)
ParameterValue
cp-10.04_odptime period consistent with the restoration time-periods defined in the service provider and organization Service Level Agreements
IA

IA Family

7 controls
IA-2(6)
ParameterValue
ia-02.06_odp.01local, network and remote
ia-02.06_odp.02privileged accounts; non-privileged accounts
IA-2(8)
ParameterValue
ia-02.08_odpprivileged accounts; non-privileged accounts
IA-4(4)
ParameterValue
ia-04.04_odpcontractors; foreign nationals
IA-5

Varies by class

B
  • Authenticators must be compliant with NIST SP 800-63-3 Digital Identity Guidelines IAL, AAL, FAL level 1. Link https://pages.nist.gov/800-63-3
  • IA-5 Guidance: SP 800-63C Section 6.2.3 Encrypted Assertion requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE).
C
  • Authenticators must be compliant with NIST SP 800-63-3 Digital Identity Guidelines IAL, AAL, FAL level 2. Link https://pages.nist.gov/800-63-3
  • IA-5 Guidance: SP 800-63C Section 6.2.3 Encrypted Assertion requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE).
D
  • Authenticators must be compliant with NIST SP 800-63-3 Digital Identity Guidelines IAL, AAL, FAL level 3. Link https://pages.nist.gov/800-63-3
  • IA-5 Guidance: SP 800-63C Section 6.2.3 Encrypted Assertion requires that authentication assertions be encrypted when passed through third parties, such as a browser. For example, a SAML assertion can be encrypted using XML-Encryption, or an OpenID Connect ID Token can be encrypted using JSON Web Encryption (JWE).
IR

IR Family

24 controls
IR-1

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-2

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-2(1)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-2(2)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-3

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-3(2)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-4

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-4(1)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-4(2)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-4(4)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-4(6)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-4(11)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-5

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-5(1)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-6

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-6(1)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-6(3)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-7

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-7(1)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-8

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-9

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-9(2)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-9(3)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
IR-9(4)

Guidance

  • Follow the FedRAMP Incident Evaluation and Reporting rules.
MA

MA Family

2 controls
MA-5

Guidance

  • CSPs should clearly document nationality requirements (or lack of) for maintenance personnel where applicable.
MA-5(1)

Guidance

  • Only MA-5 (1) (a) (1) is required by FedRAMP Class C Baseline.
PS

PS Family

1 controls
PS-7

Guidance

  • CSPs MUST clearly document any nationality requirements for any account type within its platform. If none exists, this must also be explicitly stated.
RA

RA Family

8 controls
RA-5

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
RA-5(2)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
RA-5(3)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
RA-5(4)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
RA-5(5)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
RA-5(8)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
RA-5(11)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
RA-7

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
SA

SA Family

3 controls
SA-5

Guidance

  • Follow the FedRAMP Secure Configuration Guide rules.
SA-9(2)
ParameterValue
sa-09.02_odpall external systems where federal customer data is processed or stored
SA-9(5)

Varies by class

C
  • sa-09.05_odp.01: information processing, information or data, AND system services
  • sa-09.05_odp.03: all federal customer data
D
  • sa-09.05_odp.01: information processing, information or data, AND system services
  • sa-09.05_odp.02: U.S./U.S. Territories or geographic locations where there is U.S. jurisdiction
  • sa-09.05_odp.03: all federal customer data
SC

SC Family

2 controls
SC-7

Guidance

  • SC-7 (b) may be met by using any technical capability or complement of capabilities that ensures logical separation between publicly accessible components and internal networks by preventing traversal without inspection and authorization; traffic may not flow unrestricted from publicly accessible components to internal networks.
SC-13

Guidance

  • Follow the FedRAMP Cryptographic Module Use rules.
SI

SI Family

9 controls
SI-2

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
SI-2(2)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
SI-4

Guidance

  • Follow all applicable rules within the Vulnerability and Detection Response and Incident Communication Procedure guidance.
SI-4(1)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
SI-4(2)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
SI-4(4)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
SI-4(5)

Guidance

  • Follow the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules.
SI-5

Guidance

  • Follow the FedRAMP Addressing FedRAMP Communication rules.
SI-8

Guidance

  • When CSO sends email on behalf of the government as part of the business offering, Control Description should include implementation of Domain-based Message Authentication, Reporting & Conformance (DMARC) on the sending domain for outgoing messages as described in DHS Binding Operational Directive (BOD) 18-01. https://www.cisa.gov/news-events/directives
  • SI-8 Guidance: CSPs should confirm DMARC configuration (where appropriate) to ensure that policy=reject and the rua parameter includes reports@dmarc.cyber.dhs.gov. DMARC compliance should be documented in the SI-08 control implementation solution description, and list the FROM: domain(s) when emails are sent on behalf of the government.
SR

SR Family

2 controls
SR-3

Guidance

  • CSO must document and maintain the supply chain custody, including replacement devices, to ensure the integrity of the devices before being introduced to the boundary.
SR-8

Guidance

  • Follow the FedRAMP Incident Evaluation and Communication rules.