Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Demo #620

Merged
merged 52 commits into from
Mar 30, 2024
Merged

Demo #620

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
52 commits
Select commit Hold shift + click to select a range
8646787
Update cloud-service-page.html
shivaalipour Mar 27, 2024
108820f
Update agency-authorization.html
shivaalipour Mar 27, 2024
1f20d6e
Update agency-authorization.html
shivaalipour Mar 27, 2024
39ba723
Update 2024-03-04-FedRAMP-Continuous-Monitoring-Deliverables-Template.md
shivaalipour Mar 27, 2024
1a48480
Update baselines.html
shivaalipour Mar 27, 2024
db6fdc5
Delete _team/brian_conrad.md
shivaalipour Mar 27, 2024
de4f250
Create david-waltermire.md
shivaalipour Mar 27, 2024
136d600
Update david-waltermire.md
shivaalipour Mar 27, 2024
f09b545
Dave's Bio image
shivaalipour Mar 27, 2024
c135c79
Update and rename david-waltermire.md to david_waltermire.md
shivaalipour Mar 27, 2024
4e1e9d1
Update faqs.html
shivaalipour Mar 27, 2024
e45f447
Update faqs.html
shivaalipour Mar 27, 2024
a8c84a8
Update faqs.html
shivaalipour Mar 28, 2024
7a42b7f
Update agency-authorization.html
shivaalipour Mar 28, 2024
5930c4a
Update assessor-page.html
shivaalipour Mar 28, 2024
ef2da32
Add files via upload
shivaalipour Mar 28, 2024
c14f7b5
Update footer.html
shivaalipour Mar 28, 2024
724a3e0
Add files via upload
shivaalipour Mar 28, 2024
ef1476d
Add files via upload
shivaalipour Mar 28, 2024
169ffc3
Update footer.html
shivaalipour Mar 28, 2024
19e6520
Add files via upload
shivaalipour Mar 28, 2024
a68e23f
Update faqs.html
shivaalipour Mar 28, 2024
d97343e
Update faqs.html
shivaalipour Mar 28, 2024
a9bb4c8
Add files via upload
shivaalipour Mar 29, 2024
85ddf00
Add files via upload
shivaalipour Mar 29, 2024
8f0c349
Rename 2023-08-30-FedRAMP_POAM_Template.md to 2024-03-29-FedRAMP_POAM…
shivaalipour Mar 29, 2024
238ea8d
Rename 2023-08-30-SAR-Appendix-A-FedRAMP-Risk-Exposure-Table-Template…
shivaalipour Mar 29, 2024
340e308
Update rev5-transition.html
shivaalipour Mar 29, 2024
2f43202
Update footer.html
shivaalipour Mar 29, 2024
73b2e6a
Update agency-authorization.html
shivaalipour Mar 29, 2024
c0f9b84
Add files via upload
shivaalipour Mar 29, 2024
16bfedf
Delete assets/resources/documents/3PAO_Obligations_and_Performance_Gu…
shivaalipour Mar 29, 2024
9b88282
Update 2023-04-06-3PAO_Obligations_and_Performance_Guide.md
shivaalipour Mar 29, 2024
9a0d980
Update 2023-07-20-3pao-assessment-teams-must-be-qualified.md
shivaalipour Mar 29, 2024
89c61ba
Update assessor-page.html
shivaalipour Mar 29, 2024
e9053f6
Update 2023-04-06-updated-3PAO-obligations-and-performance-standards-…
shivaalipour Mar 29, 2024
17a92f1
Update 2020-09-01-updated-3PAO-obligations-and-performance-standards-…
shivaalipour Mar 29, 2024
a6a4025
Update training.html
shivaalipour Mar 29, 2024
21dbce1
Update 2023-08-01-new-3pao-training-obligations-and-performance-stand…
shivaalipour Mar 29, 2024
ffe9d72
Update footer.html
shivaalipour Mar 29, 2024
263b1d9
Update footer.html
shivaalipour Mar 29, 2024
59656ff
Delete assets/img/FedRAMP-x.png
shivaalipour Mar 29, 2024
617ee06
Add files via upload
shivaalipour Mar 29, 2024
7d785ca
Delete assets/img/FedRAMP-x.svg
shivaalipour Mar 29, 2024
b61bce8
Update footer.html
shivaalipour Mar 29, 2024
eaf9e4d
Update footer.html
shivaalipour Mar 29, 2024
76bf38d
Add files via upload
shivaalipour Mar 29, 2024
8759e03
Add files via upload
shivaalipour Mar 29, 2024
3498216
Add files via upload
shivaalipour Mar 29, 2024
8360bbe
Add files via upload
shivaalipour Mar 29, 2024
b07137c
Update 2020-07-23-fedramp-announces-document-and-template-updates.md
shivaalipour Mar 29, 2024
201b61a
Merge pull request #619 from GSA/shivaalipour-patch-7
david-waltermire Mar 29, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 10 additions & 10 deletions _includes/footer.html
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ <h4>Follow Us</h4>
</div>
<div class="footer-social">
<p><a target="_blank" href="https://twitter.com/fedramp?lang=en">
<img src="{{site.baseurl}}/assets/img/FedRAMP_twitter.svg" alt="twitter icon" style="margin: 0px 15px 0px 0px; position: relative; top: 8px;}"> Twitter
<img src="{{site.baseurl}}/assets/img/FedRAMP_twitter.svg" alt="x icon" style="margin: 0px 15px 0px 0px; position: relative; top: 8px;}"> X
</a></p>
<p><a target="_blank" href="https://www.youtube.com/c/FedRAMP?lang=en">
<img src="{{site.baseurl}}/assets/img/FedRAMP-youtube.svg" alt="youtube icon" style="margin: 0px 15px 0px 0px; position: relative; top: 8px;"> YouTube
Expand Down Expand Up @@ -97,7 +97,7 @@ <h4>Keep Up To Date</h4>
<div class="usa-identifier__identity" aria-label="Agency description">
<p class="usa-identifier__identity-domain">FedRAMP.gov</p>
<p class="usa-identifier__identity-disclaimer">
An official website of the GSA’s <a href="https://www.gsa.gov/about-us/organization/federal-acquisition-service/technology-transformation-services" class="gov-links">Technology Transformation Services</a>
<span aria-hidden="true">An </span> official website of the GSA’s <a href="https://www.gsa.gov/about-us/organization/federal-acquisition-service/technology-transformation-services" class="gov-links">Technology Transformation Services</a>
</p>
</div>
</div>
Expand All @@ -118,8 +118,8 @@ <h4>Keep Up To Date</h4>
>
</li>
<li class="usa-identifier__required-links-item">
<a href="https://www.gsa.gov/website-information/accessibility-aids" class="usa-identifier__required-link usa-link"
>Accessibility support</a
<a href="https://www.gsa.gov/website-information/accessibility-statement" class="usa-identifier__required-link usa-link"
>Accessibility statement</a
>
</li>
<li class="usa-identifier__required-links-item">
Expand All @@ -138,20 +138,20 @@ <h4>Keep Up To Date</h4>
>
</li>
<li class="usa-identifier__required-links-item">
<a href="https://www.gsa.gov/reference/gsa-plans-and-reports" class="usa-identifier__required-link usa-link"
<a href="https://www.gsa.gov/reference/reports" class="usa-identifier__required-link usa-link"
>Performance reports</a
>
</li>
<li class="usa-identifier__required-links-item">
<a href="https://www.gsa.gov/website-information/website-policies" class="usa-identifier__required-link usa-link"
>GSA Privacy policy</a
<a href="https://www.gsa.gov/reference/gsa-privacy-program" class="usa-identifier__required-link usa-link"
>GSA privacy policy</a
>
</li>
<li class="usa-identifier__required-links-item">
<a href="https://www.gsa.gov/website-information/website-policies" class="usa-identifier__required-link usa-link"
>FedRAMP privacy policy</a
<a href="https://www.gsa.gov/vulnerability-disclosure-policy" class="usa-identifier__required-link usa-link"
>Vulnerability disclosure policy</a
>
</li>
</li>
</ul>
</div>
</nav>
Expand Down
23 changes: 6 additions & 17 deletions _layouts/agency-authorization.html
Original file line number Diff line number Diff line change
Expand Up @@ -167,7 +167,7 @@ <h3 class="margin-top-0">Full Security Assessment</h3>

<div class="full-col tablet:grid-col-7 authorization-information-col">
<h3 class="margin-top-0">Agency Authorization Process</h3>
<p>The next step is the Agency Authorization Process. During this step, the agency conducts a security authorization package review, which may include a SAR debrief with the FedRAMP PMO. Depending on the results of the agency’s review, CSP remediation may be required. Additionally, the agency will implement, test, and document customer responsible controls during this phase. Finally, the agency performs a risk analysis, accepts risk, and issues an ATO. This decision is based on the agency’s risk tolerance. Once an agency provides an ATO letter for the use of the CSO, the following actions take place to close out this step:</p>
<p>The next step is the Agency Authorization Process. During this step, the agency conducts a security authorization package review, which may include a SAR debrief. Depending on the results of the agency’s review, CSP remediation may be required. During this phase, the agency may implement, document, and test customer responsible controls. Alternatively, the agency may choose to perform these steps after issuing the ATO. Finally, the agency performs a risk analysis, accepts risk, and issues an ATO. This decision is based on the agency’s risk tolerance. Once an agency provides an ATO letter for the use of the CSO, the following actions take place to close out this step:</p>

<ul class="red-bullets">
<li>The CSP uploads the <em>Authorization Package Checklist</em> and the complete security package (SSP and attachments, POA&M, and Agency ATO letter), with exception of the security assessment material, to FedRAMP’s secure repository.</li>
Expand Down Expand Up @@ -245,17 +245,6 @@ <h3>Agency Authorization Playbook</h3>
</div>
</div>

<div class="full-row grid-row grid-gap auth-resources-row">
<div class="full-col tablet:grid-col-2 auth-pdf-download-img">
<img src="{{site.baseurl}}/assets/img/auth-pdf-download.svg" class="" alt="" />
</div>
<div class="full-col tablet:grid-col-10 padding-right-4">
<h3>Agency Authorization - Roles and Responsibilities for FedRAMP, CSPs, and Agencies</h3>
<p>This document provides a summary of the roles and responsibilities of the agency, CSP, and FedRAMP PMO during the Agency Authorization process.</p>
<p><a class="auth-resources-download" href="https://www.fedramp.gov/assets/resources/documents/Agency_Authorization_Roles_and_Responsibilities_for_FedRAMP_CSPs_and_Agencies.pdf" target="_blank">Download [PDF - 933KB]</a></p>
</div>
</div>

<div class="full-row grid-row grid-gap auth-resources-row">
<div class="full-col tablet:grid-col-2 auth-pdf-download-img">
<img src="{{site.baseurl}}/assets/img/auth-pdf-download.svg" class="" alt="" />
Expand All @@ -272,9 +261,9 @@ <h3>FedRAMP Authorization Boundary Guidance</h3>
<img src="{{site.baseurl}}/assets/img/auth-pdf-download.svg" class="" alt="" />
</div>
<div class="full-col tablet:grid-col-10 padding-right-4">
<h3>FedRAMP Guide for Multi-Agency Continuous Monitoring</h3>
<h3>FedRAMP Colllaborative ConMon Quick Guide</h3>
<p>This document provides guidance to agencies and CSPs to assist with a framework for collaboration when managing Agency ATOs.</p>
<p><a class="auth-resources-download" href="https://www.fedramp.gov/assets/resources/documents/Agency_Guide_for_Multi-Agency_Continuous_Monitoring.pdf" target="_blank">Download [PDF - 413KB]</a></p>
<p><a class="auth-resources-download" href="https://www.fedramp.gov/assets/resources/documents/FedRAMP_Collaborative_ConMon_Quick_Guide.pdf" target="_blank">Download [PDF - 413KB]</a></p>
</div>
</div>

Expand All @@ -283,9 +272,9 @@ <h3>FedRAMP Guide for Multi-Agency Continuous Monitoring</h3>
<img src="{{site.baseurl}}/assets/img/auth-visit-site.svg" class="" alt="" />
</div>
<div class="full-col tablet:grid-col-10 padding-right-4">
<h3>FedRAMP Tailored Website</h3>
<p>Provides guidance and templates for FedRAMP Tailored, a simple, condensed approach to the Authorization process for Low-Impact Software-as-a-Service (LI-SaaS) applications.</p>
<p><a class="auth-resources-download" href="https://tailored.fedramp.gov/" target="_blank">Visit Website</a></p>
<h3>FedRAMP Baselines</h3>
<p>This web page helps stakeholders understand the FedRAMP Baselines and Impact Levels for FedRAMP Authorizations</p>
<p><a class="auth-resources-download" href="https://www.fedramp.gov/baselines/"_blank">Visit Website</a></p>
</div>
</div>
</div>
Expand Down
10 changes: 5 additions & 5 deletions _layouts/assessor-page.html
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@
<p>As independent third parties, they perform initial and periodic assessments of cloud systems based on federal security requirements. The federal government uses 3PAO assessments as the basis for making informed, risk-based authorization decisions for the use of cloud products and services. During FedRAMP assessments, 3PAOs produce a Readiness Assessment Report (RAR), which is required for the Joint Authorization Board (JAB) Authorization process and optional but highly recommended for the Agency Authorization process, and/or a Security Assessment Plan (SAP) and Security Assessment Report (SAR) that is submitted for authorization to a government Authorizing Official (AO).
</p>

<p>A list of FedRAMP recognized Third Party Assessment Organizations (3PAOs) can be found on the <a href="https://marketplace.fedramp.gov/#!/assessors?sort=assessorName" target="_blank" style="cursor: pointer; text-decoration: underline; color: #c71f25;" rel="noopener">FedRAMP Marketplace</a>.
<p>A list of FedRAMP recognized Third Party Assessment Organizations (3PAOs) can be found on the <a href="https://marketplace.fedramp.gov/assessors" target="_blank" style="cursor: pointer; text-decoration: underline; color: #c71f25;" rel="noopener">FedRAMP Marketplace</a>.
</p>
</div>
</div>
Expand Down Expand Up @@ -73,10 +73,10 @@
<div class="tablet:grid-col-6">
<div class="partners-card padding-4 tablet:margin-right-2">
<h3 class="margin-top-0 margin-bottom-3">3PAO Obligations and Performance Standards</h3>
<p> The <em>3PAO Obligations and Performance Standards</em> provides guidance for 3PAOs on demonstrating the quality, independence, and FedRAMP knowledge required as they perform security assessments on cloud systems. </p>
<p> FedRAMP created a conformity assessment process to recognize third party assessment organizations (3PAOs) through accreditation by the American Association for Laboratory Accreditation (A2LA). This process ensures 3PAOs meet the necessary quality, independence, and FedRAMP knowledge requirements, to perform independent security assessments required by FedRAMP. To maintain recognition, 3PAOs must continue to demonstrate independence, quality, and FedRAMP knowledge as they perform security assessments on cloud systems.</p>
<p class="file-type">[File Info: PDF - 458KB]</p>
<div class="margin-top-4 margin-bottom-2">
<a class="partners-download policy-pdf" href="{{site.baseurl}}/assets/resources/documents/3PAO_Obligations_and_Performance_Guide.pdf" target="_blank">Download</a>
<a class="partners-download policy-pdf" href="{{site.baseurl}}/assets/resources/documents/3PAO_Obligations_and_Performance_Standards.pdf" target="_blank">Download</a>

Check warning

Code scanning / CodeQL

Potentially unsafe external link Medium

External links without noopener/noreferrer are a potential security risk.
</div>
</div>

Expand All @@ -85,8 +85,8 @@
<div class="tablet:grid-col-6 partners-card-mobile-row ">
<div class="partners-card padding-4 tablet:margin-left-2 mobile:margin-top-2 tablet:margin-top-0">

<h3 class="margin-top-0 margin-bottom-3"> FedRAMP Readiness Assessments: A Guide for 3PAOs </h3>
<p> The <em>FedRAMP Readiness Assessments: A Guide for 3PAOs</em> provides 3PAOs with guidance on how best to utilize the RAR. It provides a shared understanding of the RAR’s intent, process, and best practices.</p>
<h3 class="margin-top-0 margin-bottom-3"> 3PAO Readiness Assessment Report Guide</h3>
<p> FedRAMP created the Readiness Assessment Report Guide to assist 3PAOs and cloud service providers on how to best utilize the FedRAMP Readiness Assessment Report (RAR) templates to confirm the full implementation of the CSO’s technical capabilities, which is required for a FedRAMP Readiness Assessment to be successful. This also helps 3PAOs and CSPs understand the rigor that FedRAMP requires for assessments.</p>
<p class="file-type">[File Info: PDF - 342KB]</p>
<div class="margin-top-4 margin-bottom-2">
<a class="partners-download policy-pdf" href="{{site.baseurl}}/assets/resources/documents/3PAO_Readiness_Assessment_Report_Guide.pdf" target="_blank">Download</a>
Expand Down
2 changes: 1 addition & 1 deletion _layouts/baselines.html
Original file line number Diff line number Diff line change
Expand Up @@ -184,7 +184,7 @@ <h3 class="margin-top-0">High Impact Level</h3>
<div class="grid-container">
<div class="full-row grid-row">
<div class="full-col desktop:grid-col-12">
<p>CSPs should use the FedRAMP FIPS 199 Categorization Template (Attachment 10) in the SSP along with the guidance of <a href="http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v2r1.pdf" target="_blank">NIST Special Publication 800-60 volume 2 Revision 1</a> to correctly categorize their system based on the types of information processed, stored, and transmitted on their systems. Customer agencies are expected to perform a separate FIPS 199 analysis for their own data hosted in the CSP’s cloud environment.</p>
<p>CSPs should use the FedRAMP FIPS 199 Categorization Template (Appendix K) in the SSP along with the guidance of <a href="http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v2r1.pdf" target="_blank">NIST Special Publication 800-60 volume 2 Revision 1</a> to correctly categorize their system based on the types of information processed, stored, and transmitted on their systems. Customer agencies are expected to perform a separate FIPS 199 analysis for their own data hosted in the CSP’s cloud environment.</p>

<p>CSPs can achieve a FedRAMP Authorized designation via the Agency Path for any of the baselines (LI-SaaS, Low, Moderate, High). CSPs can only pursue a FedRAMP Authorized designation via the JAB Path for the Moderate and High baselines.</p>
</div>
Expand Down
2 changes: 1 addition & 1 deletion _layouts/cloud-service-page.html
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,7 @@
<p>The <em>CSP Authorization Playbook: Getting Started with FedRAMP</em> provides CSPs with an overview of how to develop an authorization strategy, the types of authorizations, and important considerations for their CSOs when working with FedRAMP.</p>
<p class="file-type">[File Info: PDF - 959KB]</p>
<div class="margin-top-4 margin-bottom-2">
<a class="partners-download policy-pdf" href="{{site.baseurl}}/assets/resources/documents/CSP_Authorization_Playbook_Getting_Started_with_FedRAMP.pdf" target="_blank">Download</a>
<a class="partners-download policy-pdf" href="{{site.baseurl}}/assets/resources/documents/CSP_Authorization_Playbook.pdf" target="_blank">Download</a>

Check warning

Code scanning / CodeQL

Potentially unsafe external link Medium

External links without noopener/noreferrer are a potential security risk.
</div>
</div>

Expand Down
Loading