-
Notifications
You must be signed in to change notification settings - Fork 10
Open
Description
This Request for Comment (or set of RFCs) related to the FedRAMP Marketplace and authorization designations will attempt to address many gaps in the current process. Goals for this RFC include:
- Adding a "Preparation" step aligned with the NIST RMF Step 1 that will allow any cloud service provider to publicly attest that they are carrying out the essential activities to prepare their cloud service offering for a FedRAMP authorization.
- Replacing "FedRAMP Ready" with a CSP + 3PAO attested "Independently Assessed" state.
- Adding a "Remediation" status
- Replacing final status with "Continuous Monitoring" and "Persistent Validation" instead of "authorized"
- Renaming "In Process" to "Agency Authorization In Process" for Rev5
Plus supporting requirements for these various states and a few other interesting things.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
Public Action