Security & Compliance
Lynx Compliance - FedRAMP 20x
FedRAMP 20x Key Security Indicators as an overlay on NIST SP 800-53 - each indicator cross-referenced to the underlying controls, so an existing 800-53 profile carries straight over.
lynx_compliance_fedramp
· v19.0.1.0.0
· Add-on
Beta
What this solves
Lynx Compliance - FedRAMP 20x
FedRAMP authorisation has always been NIST SP 800-53 plus a baseline plus a process. FedRAMP 20x changes the process: instead of narrating every control in a document nobody rereads, a cloud service provider validates a set of Key Security Indicators continuously, in a form a machine can check.
This pack ships those indicators as assessable controls. It is an overlay, not a second copy of 800-53. Every indicator carries the 800-53 control codes it evidences, and those codes match the ones in lynx_compliance_nist_80053 exactly, so the crosswalk pairs them in both directions. A provider who has already assessed AC-2 does not assess it again to answer the identity indicators.
The pack also carries the authorisation artefacts that sit around the indicators - categorisation, baseline tailoring, the System Security Plan, the POA&M and continuous monitoring - because those are what an assessor asks for and they are not indicators themselves.
Accuracy note: FedRAMP is actively iterating 20x. The indicator set here reflects the Phase One release covering Low impact. Validate it against FedRAMP's current publication before relying on it for a live authorisation.
Key Features
42 controls across five functions - ten Key Security Indicator families plus the authorisation artefacts.
Cross-referenced to NIST SP 800-53 by control code - AC-2, SI-4, CP-9 and the rest, matching the codes shipped by the 800-53 pack, so assessments propagate automatically.
Overlay, not a duplicate - the 296 controls of 800-53 are not re-seeded, so a provider holding both packs assesses each control once.
Evidence guidance naming connectors - identity, SIEM, scanner, backup and cloud connectors are named per indicator rather than "collect appropriate evidence".
Authorisation artefacts included - FIPS 199 categorisation, baseline tailoring, SSP currency, POA&M ageing and continuous-monitoring cadence.
Residual-risk examples written as partial states - no provider is uniformly green mid-authorisation, and the examples reflect that.
Integrates With
lynx_compliance_nist_80053 - the underlying baseline this overlays; install both for the crosswalk to do its work.
lynx_compliance - CSF 2.0 profiles cross-reference through the shared 800-53 mappings.
lynx_compliance_evidence_collectors - continuous monitoring is the point of 20x, and scheduled collection is how it is evidenced.
Try Lynx Compliance - FedRAMP 20x on your team.
Free trial, no credit card. Talk to sales when you're ready.