Cloud Services and Inheritance
Record the cloud services a system uses, capture their SLAs and contract terms, and let control inheritance be populated from the provider's customer responsibility matrix.
A system on a cloud provider inherits a large share of its controls from the provider's own authorization. Bedrock RMF records which services the system uses and pre-populates the inherited / shared / customer split from the provider's Customer Responsibility Matrix, so those controls show up in the SCTM as Inherited or Hybrid instead of being re-implemented from scratch. Open Cloud Services in the package sidebar.
The Cloud Services page
The page reads Cloud Services — Track CSP services, SLAs, and control inheritance for this package. with Add Services top right and counts for Cloud Services, Inherited Controls, Shared Controls and Customer Controls.

The table lists Service, Category, Inherited, Shared, Customer and Total — the number of control mappings in each responsibility bucket for that service.
Adding services
Add Services opens the catalog: "Select AWS services used by this system. Control inheritance will be auto-populated from the AWS Customer Responsibility Matrix." Use Search services… and the category filter, click the rows to select them, and click Add n Services.
Search matches substrings
Typing "Amazon EC2" also lists "Amazon EC2 Image Builder". Check the row you click before adding — removing a wrong service later is one click on its page, but its mappings will have been counted in the meantime.
A service's page

The service page shows the name, AWS and category badges, and Remove,
followed by:
- SLA & Contract Details — Availability SLA, RTO (hours), RPO (hours), Incident Notification, Vuln Remediation SLA, Contract Reference, Notes, and Save SLA Details. These are the figures a CP / IR assessor will ask you to substantiate.
- Control Inheritance Summary — Inherited / Shared / Customer / Total Mappings.
- Documents (n) — a type combobox (
crm…) and Upload — "Upload CRM documents, SLA contracts, authorization letters…". Keep the provider's CRM and its authorization letter here; they are the evidence for every inherited control. - Control Inheritance (n controls) — the full mapping table for the service.
Inherited and shared mappings are what let you set a control's TYPE to Inherited or Hybrid in the SCTM with a straight face; the customer bucket is the list of what remains yours to implement.