Skip to content
Foxx Cyberfoxxcyber/docs

Cloud Services and Inheritance

Record the cloud services a system uses, capture their SLAs and contract terms, and let control inheritance be populated from the provider's customer responsibility matrix.

A system on a cloud provider inherits a large share of its controls from the provider's own authorization. Bedrock RMF records which services the system uses and pre-populates the inherited / shared / customer split from the provider's Customer Responsibility Matrix, so those controls show up in the SCTM as Inherited or Hybrid instead of being re-implemented from scratch. Open Cloud Services in the package sidebar.

The Cloud Services page

The page reads Cloud Services — Track CSP services, SLAs, and control inheritance for this package. with Add Services top right and counts for Cloud Services, Inherited Controls, Shared Controls and Customer Controls.

The Cloud Services list with per-service inherited, shared and customer control counts

The table lists Service, Category, Inherited, Shared, Customer and Total — the number of control mappings in each responsibility bucket for that service.

Adding services

Add Services opens the catalog: "Select AWS services used by this system. Control inheritance will be auto-populated from the AWS Customer Responsibility Matrix." Use Search services… and the category filter, click the rows to select them, and click Add n Services.

Search matches substrings

Typing "Amazon EC2" also lists "Amazon EC2 Image Builder". Check the row you click before adding — removing a wrong service later is one click on its page, but its mappings will have been counted in the meantime.

A service's page

A cloud service's page with SLA details, inheritance summary, documents and the control inheritance table

The service page shows the name, AWS and category badges, and Remove, followed by:

  • SLA & Contract Details — Availability SLA, RTO (hours), RPO (hours), Incident Notification, Vuln Remediation SLA, Contract Reference, Notes, and Save SLA Details. These are the figures a CP / IR assessor will ask you to substantiate.
  • Control Inheritance Summary — Inherited / Shared / Customer / Total Mappings.
  • Documents (n) — a type combobox (crm …) and Upload — "Upload CRM documents, SLA contracts, authorization letters…". Keep the provider's CRM and its authorization letter here; they are the evidence for every inherited control.
  • Control Inheritance (n controls) — the full mapping table for the service.

Inherited and shared mappings are what let you set a control's TYPE to Inherited or Hybrid in the SCTM with a straight face; the customer bucket is the list of what remains yours to implement.

Last updated August 27, 2026