Control Evidence Mappings
Each control mapping documents what evidence Vallum produces to support your compliance program, what it does not produce, known limitations, and what remains your responsibility.
Published (25)
FedRAMP-AC-2(H): Manage system accounts with enhanced controls for high-impact systems
FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED
FedRAMP-AC-3(H): Enforce approved authorizations with mandatory access control for high-impact data
FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED
FedRAMP-AC-6(H): Employ least privilege with enhanced restrictions for high-impact operations
FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED
FedRAMP-AU-2(H): Identify auditable events with expanded scope for high-impact systems
FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED
FedRAMP-AU-3(H): Generate detailed audit records for all security-relevant events
FedRAMP Rev 5 High · SUPPORTED EVIDENCE · TESTED
FedRAMP-AU-6(H): Review and correlate audit records with automated analysis tools
FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED
FedRAMP-AU-9(H): Protect audit information with cryptographic integrity verification
FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED
FedRAMP-AU-12(H): Generate audit records at all system components with centralized collection
FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED
FedRAMP-CA-7(H): Implement continuous monitoring with automated assessment capabilities
FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED
FedRAMP-CM-2(H): Maintain baseline configurations with automated drift detection
FedRAMP Rev 5 High · PARTIAL TECHNICAL SUPPORT · SUPPORTED
FedRAMP-CM-6(H): Enforce configuration settings with automated compliance verification
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-IA-2(H): Implement multi-factor authentication for all access to high-impact systems
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-IA-5(H): Manage authenticators with enhanced rotation and complexity requirements
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SC-7(H): Implement boundary protection with enhanced monitoring at all external interfaces
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SC-8(H): Protect transmitted information with FIPS-validated cryptography
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SC-12(H): Establish and manage cryptographic keys with FIPS-compliant key management
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SC-13(H): Implement FIPS-validated cryptographic mechanisms for all data protection
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SC-28(H): Protect information at rest with FIPS-validated encryption
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SI-4(H): Implement system monitoring with real-time alerting for high-impact events
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SI-7(H): Employ integrity verification with automated response to detected changes
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-IR-4(H): Implement incident response with automated containment for high-impact systems
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-AC-11(H): Enforce session termination after defined inactivity period for privileged sessions
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-AC-5(H): Implement separation of duties with automated enforcement for critical operations
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-CA-3(H): Maintain system interconnection agreements with continuous authorization monitoring
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT
FedRAMP-SR-3(H): Implement supply chain risk management with provenance verification for components
FedRAMP Rev 5 High · INTEGRATION REQUIRED · PILOT