Skip to content

RFC: New Marketplace and Authorization Designations #95

@pete-gov

Description

@pete-gov

This Request for Comment (or set of RFCs) related to the FedRAMP Marketplace and authorization designations will attempt to address many gaps in the current process. Goals for this RFC include:

  • Adding a "Preparation" step aligned with the NIST RMF Step 1 that will allow any cloud service provider to publicly attest that they are carrying out the essential activities to prepare their cloud service offering for a FedRAMP authorization.
  • Replacing "FedRAMP Ready" with a CSP + 3PAO attested "Independently Assessed" state.
  • Adding a "Remediation" status
  • Replacing final status with "Continuous Monitoring" and "Persistent Validation" instead of "authorized"
  • Renaming "In Process" to "Agency Authorization In Process" for Rev5

Plus supporting requirements for these various states and a few other interesting things.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Public Action

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions