KSI Example

WORK IN PROGRESS

The OSCAL Foundation's FedRAMP TFG elected to focus on [KSI-IAM-AAM] Identity and Access Management: Automated Account Management.

This is an example of how KSIs could be implemented in OSCAL. It does not necessary reflect exactly what should be collected or how.


KSI-IAM-AAM

The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.

The 
 - lifecycle and
    - privileges of
 - all accounts, roles, and groups 
 - are securely managed 
   - using automation.

Subjects

Evidence

Appropriate Triggers Might Include

Assumptions and Prerequisites

The automated workflow:

Correlation

Questions to Answer

OSCAL High-Level Concept

cATO_ERD.png

NOTES


Revision #2
Created 2026-08-20 19:42:19 UTC by Brian Ruf
Updated 2026-08-31 19:11:43 UTC by Brian Ruf