<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>FedRAMP on The Final Hour</title><link>https://lpri.me/tags/fedramp/</link><description>Recent content in FedRAMP on The Final Hour</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 23 Jul 2026 06:24:09 +0000</lastBuildDate><atom:link href="https://lpri.me/tags/fedramp/index.xml" rel="self" type="application/rss+xml"/><item><title>Understanding Key Security Indicators (KSIs)</title><link>https://lpri.me/posts/ksi-key-security-indicators/</link><pubDate>Thu, 23 Jul 2026 06:24:09 +0000</pubDate><guid>https://lpri.me/posts/ksi-key-security-indicators/</guid><description>&lt;p&gt;FedRAMP 20X is sort of around the corner, switching from the old approach of framework reliance to the new evidence-based verification method. In plain English, instead of checking the Implemented box on the SSP, you now have to provide machine-readable evidence. There are 46 KSIs, and every one will require persistent evaluation. Start preparing now, because this process will become exponentially more expensive year over year. I have warned people about the inflation for over a decade; I have always been proven right.&lt;/p&gt;
&lt;p&gt;What if you don&amp;rsquo;t care about FedRAMP? If you want/need to be NIST compliant and/or you are taking your security posture seriously, you should start to implement at least a limited set of indicators now, targeting a full implementation by the end of 2027. This method of compliance testing is going to be the norm going forward.&lt;/p&gt;</description></item></channel></rss>