FedRAMP
Understanding Key Security Indicators (KSIs)
FedRAMP 20X is sort of around the corner, switching from the old approach of framework reliance to the new evidence-based verification method. In plain English, instead of checking the Implemented box on the SSP, you now have to provide machine-readable evidence. There are 46 KSIs, and every one will require persistent evaluation. Start preparing now, because this process will become exponentially more expensive year over year. I have warned people about the inflation for over a decade; I have always been proven right.
What if you don’t care about FedRAMP? If you want/need to be NIST compliant and/or you are taking your security posture seriously, you should start to implement at least a limited set of indicators now, targeting a full implementation by the end of 2027. This method of compliance testing is going to be the norm going forward.