diff --git a/_layouts/home-new.html b/_layouts/home-new.html index 8101c485b..5de703ace 100644 --- a/_layouts/home-new.html +++ b/_layouts/home-new.html @@ -7,14 +7,14 @@

Join the Team

-

We’re hiring a FedRAMP Director to help lead the transformation of the program. Sign up to be notified when this position is open for applications.

- -

Want to talk to us about other roles? Stop by our booth at the Tech to Gov hiring fair on April 18th. We are looking for talent that can help us build the data- and API-driven future of FedRAMP.

+

We’re hiring a Cyber Data Engineer to lead in the development of intuitive data products to help the federal government make risk management decisions.

+ +

We’re hiring a Cyber Data Analyst to play a key role in building the data- and API-driven FedRAMP of the future.

 -

View the Position

+

View All Positions

diff --git a/_layouts/rev5-transition.html b/_layouts/rev5-transition.html index 7c2369d28..2132f3768 100644 --- a/_layouts/rev5-transition.html +++ b/_layouts/rev5-transition.html @@ -183,7 +183,7 @@

Documents

FedRAMP Laws, Regulations, Standards and Guidance Reference FedRAMP Plan of Action and Milestones (POA&M) Template - FedRAMP Plan of Action and Milestones (POA&M) Template (updated 3/29/2024) + FedRAMP Plan of Action and Milestones (POA&M) Template (updated 3/29/2024) FedRAMP Guide for Multi-Agency Continuous Monitoring diff --git a/_policy/2024-03-29-FedRAMP_POAM_Template.md b/_policy/2024-03-29-FedRAMP_POAM_Template.md index 319f357a7..224218285 100644 --- a/_policy/2024-03-29-FedRAMP_POAM_Template.md +++ b/_policy/2024-03-29-FedRAMP_POAM_Template.md @@ -3,7 +3,7 @@ layout: policy title: FedRAMP Plan of Action and Milestones (POA&M) Template category: Authorization Phase weblink: -filename: templates/FedRAMP-POAM-Template.xlsm +filename: templates/FedRAMP-POAM-Template.xlsx filetype: excel fileinfo: excel - 74KB condition: update diff --git a/_posts/2022-03-08-fedramp-bod-22-01-guidance.md b/_posts/2022-03-08-fedramp-bod-22-01-guidance.md index 2896777f4..a6b580a3f 100644 --- a/_posts/2022-03-08-fedramp-bod-22-01-guidance.md +++ b/_posts/2022-03-08-fedramp-bod-22-01-guidance.md @@ -17,7 +17,7 @@ On November 3, 2021, DHS CISA issued FedRAMP, in accordance with Binding Operational Directive 22-01 and in consultation with the JAB and DHS CISA, emphasized that CSPs who maintain federal information fall within the scope defined by the BOD. All CSPs must review and implement the actions described within. -FedRAMP notified all Authorized CSPs that in order to address the requirement, FedRAMP has updated the POA&M template to accommodate tracking of vulnerabilities against the catalog of known exploited vulnerabilities. CSPs can track vulnerabilities in the new template or simply add a column (column AB, with the header ‘Binding Operational Directive 22-01 tracking’) in their current POA&M. This new column should be filled out with a ‘Yes’ or ‘No’ as to whether this POA&M item’s vulnerability is found in the catalog of known exploited vulnerabilities. +FedRAMP notified all Authorized CSPs that in order to address the requirement, FedRAMP has updated the POA&M template to accommodate tracking of vulnerabilities against the catalog of known exploited vulnerabilities. CSPs can track vulnerabilities in the new template or simply add a column (column AB, with the header ‘Binding Operational Directive 22-01 tracking’) in their current POA&M. This new column should be filled out with a ‘Yes’ or ‘No’ as to whether this POA&M item’s vulnerability is found in the catalog of known exploited vulnerabilities. CSPs should **only** include applicable vulnerabilities in their POA&M. They do not have to include a status for every known vulnerability on the CISA-managed catalog. diff --git a/_posts/2022-06-28-update-poam-template.md b/_posts/2022-06-28-update-poam-template.md index d3d573760..ee16aea17 100644 --- a/_posts/2022-06-28-update-poam-template.md +++ b/_posts/2022-06-28-update-poam-template.md @@ -6,7 +6,7 @@ image: /assets/img/blog-images/FRblog_Doc-Updates.png author: FedRAMP layout: blog-page --- -FedRAMP updated the Plan of Actions and Milestones (POA&M) template to include two new columns. The additional columns were added at the behest of agency partners to help them track Cybersecurity and Infrastructure Security Agency (CISA) Binding Operational Directive (BOD) 22-01 findings, and the associated Common Vulnerabilities and Exposures (CVEs). +FedRAMP updated the Plan of Actions and Milestones (POA&M) template to include two new columns. The additional columns were added at the behest of agency partners to help them track Cybersecurity and Infrastructure Security Agency (CISA) Binding Operational Directive (BOD) 22-01 findings, and the associated Common Vulnerabilities and Exposures (CVEs).

What’s New?

- **Column ‘AC’:** Titled as the ‘Binding Operational Directive 22-01 Due Date’ should be used to track the due date of any BOD 22-01 vulnerability as the due date appears in the CISA Known Exploited Vulnerabilities Catalog. If the POA&M line item is not associated with any BOD 22-01 vulnerability, this cell should be left blank. diff --git a/assets/resources/templates/FedRAMP-POAM-Template.xlsm b/assets/resources/templates/FedRAMP-POAM-Template.xlsm deleted file mode 100644 index 1a2eed895..000000000 Binary files a/assets/resources/templates/FedRAMP-POAM-Template.xlsm and /dev/null differ