Change Management — FedRAMP KSI Domain
Generated from the official FedRAMP/rules GitHub repo. Source path:
fedramp-consolidated-rules.jsononmainat blob7d628b63fdd9. Consolidated Rules version:2026.07.02.02· upstreamlast_updated:2026-07-02. Supporting narrative documentation is available from the officialFedRAMP/2026-markdownrepository.
Change Management
Domain code: CMT · Domain ID: KSI-CMT · Web slug: change-management
Indicators
KSI-CMT-LMC — Logging Changes
Modifications to the cloud service offering are logged and monitored.
Mapped Rev5 controls: au-2, cm-3, cm-3.2, cm-4.2, cm-6, cm-8.3, ma-2
Terms: Cloud Service Offering
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-CMT-RMV — Redeploying vs Modifying
Changes to machine-based information resources are executed through the redeployment of version controlled resources rather than direct modification wherever reasonable.
Mapped Rev5 controls: cm-2, cm-3, cm-5, cm-6, cm-7, cm-8.1, si-3
Terms: Information Resource, Machine-Based (Information Resources)
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-CMT-RVP — Reviewing Change Procedures
The effectiveness of documented change management procedures is persistently reviewed.
Mapped Rev5 controls: cm-3, cm-3.2, cm-3.4, cm-5, cm-7.1, cm-9
Terms: Persistently
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
KSI-CMT-VTD — Validating Throughout Deployment
Persistent testing and validation of changes throughout deployment is automated.
Mapped Rev5 controls: cm-3, cm-3.2, cm-4.2, si-2
Terms: Persistently, Validation
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.