From 86467875732b13d314cb2f635d580db87a5fbabb Mon Sep 17 00:00:00 2001 From: shivaalipour <87869948+shivaalipour@users.noreply.github.com> Date: Wed, 27 Mar 2024 01:43:06 -0400 Subject: [PATCH 01/51] Update cloud-service-page.html content policy changes --- _layouts/cloud-service-page.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/_layouts/cloud-service-page.html b/_layouts/cloud-service-page.html index deaf026c0..7eab57803 100644 --- a/_layouts/cloud-service-page.html +++ b/_layouts/cloud-service-page.html @@ -68,7 +68,7 @@
The CSP Authorization Playbook: Getting Started with FedRAMP provides CSPs with an overview of how to develop an authorization strategy, the types of authorizations, and important considerations for their CSOs when working with FedRAMP.
[File Info: PDF - 959KB]
From 108820f228fc556d1aa97de53f57643739e0876c Mon Sep 17 00:00:00 2001 From: shivaalipour <87869948+shivaalipour@users.noreply.github.com> Date: Wed, 27 Mar 2024 01:52:12 -0400 Subject: [PATCH 02/51] Update agency-authorization.html remove reference to tailored website --- _layouts/agency-authorization.html | 11 ----------- 1 file changed, 11 deletions(-) diff --git a/_layouts/agency-authorization.html b/_layouts/agency-authorization.html index 43f4bbe87..e30b8755a 100644 --- a/_layouts/agency-authorization.html +++ b/_layouts/agency-authorization.html @@ -277,17 +277,6 @@Provides guidance and templates for FedRAMP Tailored, a simple, condensed approach to the Authorization process for Low-Impact Software-as-a-Service (LI-SaaS) applications.
- -The next step is the Agency Authorization Process. During this step, the agency conducts a security authorization package review, which may include a SAR debrief with the FedRAMP PMO. Depending on the results of the agency’s review, CSP remediation may be required. Additionally, the agency will implement, test, and document customer responsible controls during this phase. Finally, the agency performs a risk analysis, accepts risk, and issues an ATO. This decision is based on the agency’s risk tolerance. Once an agency provides an ATO letter for the use of the CSO, the following actions take place to close out this step:
+The next step is the Agency Authorization Process. During this step, the agency conducts a security authorization package review, which may include a SAR debrief. Depending on the results of the agency’s review, CSP remediation may be required. During this phase, the agency may implement, document, and test customer responsible controls. Alternatively, the agency may choose to perform these steps after issuing the ATO. Finally, the agency performs a risk analysis, accepts risk, and issues an ATO. This decision is based on the agency’s risk tolerance. Once an agency provides an ATO letter for the use of the CSO, the following actions take place to close out this step:
CSPs should use the FedRAMP FIPS 199 Categorization Template (Attachment 10) in the SSP along with the guidance of NIST Special Publication 800-60 volume 2 Revision 1 to correctly categorize their system based on the types of information processed, stored, and transmitted on their systems. Customer agencies are expected to perform a separate FIPS 199 analysis for their own data hosted in the CSP’s cloud environment.
+CSPs should use the FedRAMP FIPS 199 Categorization Template (Appendix K) in the SSP along with the guidance of NIST Special Publication 800-60 volume 2 Revision 1 to correctly categorize their system based on the types of information processed, stored, and transmitted on their systems. Customer agencies are expected to perform a separate FIPS 199 analysis for their own data hosted in the CSP’s cloud environment.
CSPs can achieve a FedRAMP Authorized designation via the Agency Path for any of the baselines (LI-SaaS, Low, Moderate, High). CSPs can only pursue a FedRAMP Authorized designation via the JAB Path for the Moderate and High baselines.
MmjInm*>V_||KlcJS
z|5nvy0qUq2R{BxJ`Ex9>hJpg?D&~pbK5dU65&@zHrVv8S8x%k_IlffQWf4lB)+I5m
z1z<6 ;_t*cMTqWMyDk)WlDe@#SM93UzdLiKz$I$+@_Xw53B
z#?nq&F95FYl2njy&BZEUZXr_}ut2$`PDCK20xl$}_rx$yCdl1$#Q*dE_}@@o$)=ki
zbvBtsoB+OxILZZTil)N2S#IVzu4vB#Hg@
zDfX87u44d^Wk7s&eXa81>gv^D`~3WP+Z@f!S6?Wl@9#b?7L~JfY>yWg7tVIM){FJ>
zaQC=B?uZDKyn21TUT&07%hj5K-yQbW+QnkAT+|7^UZaqCo_B4l
zgfOP>58Lk8{PG|E{-+;)IBuWwA}{l@+3gN}|8(pRtuf>aomFM7lqB-TnDym_cj4}7
zr={$SlR^Mu?>vX0O;{F6Xwi3s9GJOY)F{Z>u*%fu@7}FmU&*XqR0~wn6ESm^WvSfz
zbYKe8$~Gwz5k&|g6*#}ZKMx~6g(CWPC17BVxYGD4P3uymaZl$Jm@xP!r&36p9D_@I
zSfk){jY0r`5D^PNe`7|FZ2T1G_mY64f%9Z>W&mVDKssBU((~?g_0A5m0uY&fGPzHw
z6+99Sq7VEeR%%EqPbmwh$a$D^+fUa_is`0=C-p=K0Y*Z@^ub?D;rXSsf4J|X{xMZx
zq>l&1Q)Yt1I8mnxj9|1eO7tYf{#0AQbBBWm3HkWE;k3k#XIDmnApuB#wQE@%N`Gz=}E6X>>a0q9Mw38dgDU(y;vIo8QUgrY0mW8l8}{QDXeXrkhPK
zYtN}PPHBnL)jTUmPg@ZpR%d)F*qMsBq{igY9gyDUaYsjtT8i=G#Z6I-eS4X*BgcSa
zLLrFKxRfdHdkE1OH&h-y6co|)oRFlZD&)mygG631(P?QELkz5^ HY;4pYEO>*jMyCtQYZ
zUm+G2!}Eou|17VNd5J&wc%vYW^4pSI*mDZiRGlqo&$KxuMM3pB~4J|$lvkZ2c
z{Dh;77Qsw?HeQ;7cm_7i851)yWe&esm^|^BP IUzVj~_m~XHJ}?ZwGWm+x9Pi_4f9D^Xc6$g)x15N{QEZH|zEK^N&9Y
z=w`e5@Z--u1nUY_ZQI_uvM60ym8 qBM}ROf}v4YZeV2o0|HNb$sFjJXN&oc#JF(C0U#?aENT{s7N^$u6y}?ikWS1#
zQ56tC$i^AW`bq#ZMsxxrpep0!>V&1c9+o5`03b9I#qlfhzzgJHzGYs*17`i>nMv?$
z?7!d(FV5seAA6OYc~<8EnClGWi$KmRB_mBX)XNEqEW2EodiDRa5Oq4d;gZxm@c_^A
zc$gqY^SL+&6<>%Bm8Z{kVez=MZknZ^@vKgrE^PDX@4vqUTf&Tdo@q;qhC9E@GJ*ll
z^ZYTJi^fGb%qa|WfJolH&1|U2f4n3#Pm$R(3KT&m9RrQPf!t${l!z(&ah9>LyOXGG(D+6JB`Hm9hY8rZiq?TD8=L>Y
{_
z;`*<}Vl52`7pInH9EJegF0m_i641Vt3ld76lWbzeBI
z@@2eny@OgbuPBG!XlP*pxAfat1kS9Xw+Ex4%uTrF%-ZZ^Dd!F?heoad080_B=Z@BD
z@HH`u2|qLOdC3o3i4I;Na17xNzkc`KHI{M}GQk;4a)l+9fLk3d#a3zCjL;R7RP_|L-0Q0?^Bb3A;#zHu
zZpU(=qNvx^tETF2>IY|ENp1{~G_-}vvz&L3001BWNkl
woB#J;|NH6X
zMFGa?(h-2@)6=KS;
zP4X)w4__KOi##_veTk{~pS4g@{Y-V8>gDL|xg*tcsE|dB 83Jp2n%~21Fz#MTjw)zb_>1Om;GzWu6X)r^jD@nqHoM`uh*_bbfeveE$6O%i{y>
zZ@&25@3aedZ{B?MyZ>}|f3K*0H@qBAA7372x4--F<;TwtQG~dg=IP~l9QIq{4!L{t
z=KkgRX*`}{oKi{z@ci_2oM!Dh=J5WjuSMbgyZ8J3{`-IX_s8eQFMso!H*elh(x=Bq
z5#8PF#(CtxUFhDvd*656e$)N%=YM;7c@Ri9`%R3ruYe
zFZ{}LaMa6NJ9<^4vyoCibX1B=;E{3q6Kjl#$^hd)NTdp;`7xWf-znlzyI*#4;~4X?z?We*;GZ*Hceyt)#m!EuYY|!JU{(>
z`}Fa)T(4ihyW!rp-W8elo!vd(Ki}VyLJDG0Rm*z0-|d~ZP2YnMKG34jRgvX+_Vt%v
z?zY?gelLY6io%6(_w?jE_aXGgEEd)A&}^H|*dPR7trph%SC<#BE;e~ycxU=H1oj`F
zch>q`sW%tJ>#OxIKL4UUHn+Q-bL1%)H>i4)fKsdLO|_}>N^771fdq)a5ktbvr~oph
z7=Z}{vmg$EoF@<9VootI3zUKxsJFJ=9-L`|wOLkbtz%NmK;%DtywgR0Vlza87b8++
zKmn)c*c4QJme=qyMqvW~oelES1v3Sz#t#|aRZgVYU?XeXq3&t_Bvu?S(D9Q>5lu}uiH^&12Xsx6afxMJbpy>N9
zGWebz?v)gmmzSpN-v97d7GQ~#l693=i#p4)zH6Jdsj50JD{t)MerJPY
{D1ESmBZ@1gcci;Wt-7o)rc-Y