FedRAMP-3PAO | 3PAO Assessment, FedRAMP Marketplace and Accreditation | 0 |
FedRAMP-Baselines | FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters | 28 |
FedRAMP-Boundary | Authorization Boundary, SSP, SAR, POA&M documentation | 102 |
FedRAMP-ConMon | Continuous Monitoring (ConMon) and Significant Change Requests | 72 |
FedRAMP-IncidentReporting | FedRAMP incident reporting to PMO and US-CERT | 42 |
FedRAMP-NIST-800-53-Rev5 | Coordination with NIST SP 800-53 Rev 5 + FedRAMP High + FedRAMP Moderate frameworks | 0 |
FedRAMP-OMB-M-24-15 | OMB Memorandum M-24-15 (July 2024) - FedRAMP modernization | 0 |
FedRAMP-PII-Privacy | FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act) | 37 |
FedRAMP-Program | FedRAMP Program establishment, PMO and authorization paths | 0 |
FedRAMP-StateRAMP-GovRAMP | Coordination with StateRAMP, GovRAMP and state + local + tribal government cloud authorization | 0 |
FedRAMP-Status | FedRAMP Rev 5 - corpus status, baseline references, M-24-15 modernization pipeline | 0 |
FedRAMP-SupplyChain-SBOM | FedRAMP supply chain risk management + SBOM (per EO 14028 + NIST 800-218 SSDF) | 37 |
A | Authorization process | 0 |
A.1 | A.1 CSP Information Form and FedRAMP ID | 0 |
A.10 | A.10 Secure repository and package access | 0 |
A.11 | A.11 Independence of the assessor | 0 |
A.2 | A.2 Impact level categorization | 0 |
A.3 | A.3 Deployment model, service model and system stack | 0 |
A.4 | A.4 FedRAMP Ready and the readiness assessment | 0 |
A.5 | A.5 Agency partnership, authorization planning and the In Process request | 0 |
A.6 | A.6 Kickoff meeting | 0 |
A.7 | A.7 Full security assessment | 0 |
A.8 | A.8 Agency ATO and the FedRAMP review to Authorized | 0 |
A.9 | A.9 Reuse: every agency issues its own authorization | 0 |
C | Continuous monitoring | 0 |
C.1 | C.1 Monthly continuous monitoring deliverables | 0 |
C.10 | C.10 ConMon performance management and escalation | 0 |
C.2 | C.2 Vulnerability scanning requirements | 0 |
C.3 | C.3 Scan types, POA&M entries and image scanning | 0 |
C.4 | C.4 Container requirements | 0 |
C.5 | C.5 Sampling for vulnerability scanning | 0 |
C.6 | C.6 Annual assessment | 0 |
C.7 | C.7 Significant changes: types and process | 0 |
C.8 | C.8 Incident communications | 0 |
C.9 | C.9 Collaborative continuous monitoring | 0 |
FR | FedRAMP Rev 5: the program, its parties and its status | 0 |
G | Program governance and scope under OMB M-24-15 | 0 |
G.1 | G.1 Scope of FedRAMP | 0 |
G.10 | G.10 Agency duties on oversight, metrics and cost | 0 |
G.2 | G.2 Presumption of adequacy and its limits | 0 |
G.3 | G.3 Authorization paths | 0 |
G.4 | G.4 Threat-based assessment of security postures | 0 |
G.5 | G.5 Marketplace designations, contract conditions, prioritization and temporary authorizations | 0 |
G.6 | G.6 Automation, machine-readable artifacts and OSCAL | 0 |
G.7 | G.7 Acceptance of external security frameworks and certifications | 0 |
G.8 | G.8 Continuous monitoring framework principles | 0 |
G.9 | G.9 Agency duties on authorization and reuse | 0 |
K | Cryptographic module selection and use | 0 |
K.1 | K.1 FRR1 to FRR4: documenting cryptographic module use | 0 |
K.2 | K.2 FRR5 to FRR8: assessment alignment, transition plans, monitoring visibility and public claims | 0 |
K.3 | K.3 FRR9 and FRR10: vulnerabilities in non-inherited modules | 0 |
K.4 | K.4 FRR11 to FRR14: expectations of module providers | 0 |
K.5 | K.5 FRR15 to FRR17: assessor duties | 0 |
K.6 | K.6 FRR18 to FRR21: designated leads and package reviewers | 0 |
P | Authorization package | 0 |
P.1 | P.1 Package inventory, templates and the initial checklist | 0 |
P.2 | P.2 System security plan quality | 0 |
P.3 | P.3 Authorization boundary and data flow diagrams | 0 |
P.4 | P.4 SSP appendices | 0 |
P.5 | P.5 Documenting controls in SSP Appendix A | 0 |
P.6 | P.6 Security assessment plan | 0 |
P.7 | P.7 Security assessment report | 0 |
P.8 | P.8 Plan of action and milestones | 0 |
T | Rev 5 transition and program status | 0 |
T.1 | T.1 Rev 5 baseline transition plan | 0 |