The FedRAMP abbreviation stands for...
What is Federal Risk And Authorization Management Program?
There are only 38 controls in this FedRAMP security baseline.
What is Low Impact SaaS?
According to FedRAMP vulnerability remediation guidance, low risk findings must be remediated within this number of days.
What is 180 days?
The ATO abbreviation stands for....
What is Authority to Operate?
The 3PAO abbreviation stands for....
What is Third Party Assessment Organization?
Name the NIST publication which FedRAMP uses for its risk management framework of controls.
What is NIST SP 800-53 Rev 4
There are a total of 421 controls in this FedRAMP security impact baseline.
What is the High baseline?
This document is used to track discovered vulnerabilities from security assessments.
What is a POA&M (Plan of Actions and Milestones)?
This designation denotes that a Cloud Service Offering or Cloud Service Provider is ready to be listed on the FedRAMP Marketplace and that the system has a high likelihood of obtaining a JAB P-ATO or an Agency ATO.
What is the "FedRAMP Ready" designation?
The 3PAO provides this document to the CSP which details the processes for on site visits, personnel interviews, and security scans of the information system.
What is the Security Assessment Plan?
Name the four (4) security impact baselines offered by the FedRAMP program?
What are Li-SaaS, Low, Moderate, and High?
This control in the SC family addresses the logical and physical separation of publicly accessible system components and internal organization networks, along with controlling and monitoring communications at key internal and external areas in the system.
What is SC-7 or Boundary Protection?
Unlike unauthenticated scans, these types of scans require system or application credentials to detect internal vulnerabilities.
What is an authenticated scan?
This is the name of the completed package which is submitted to the JAB or sponsoring Agency that contains the System Security Plan, Security Assessment Plan, Security Assessment Report, and Plan of Actions and Milestones.
What is the SAP or Security Authorization Package?
The 3PAO provides this document to the CSP as an analysis or report from the results of the SAP.
What is the SAR or Security Assessment Report?
True or False - FedRAMP security controls restrict data to reside only in the geographical region of the United States.
False.
This control in the AC family is about making sure that users or processes acting on behalf of users only have the minimum amount of permissions to perform mission or business functions.
What is AC-6 or Least Privilege?
The POA&M contains only these two tab names.
What are Open and Closed?
This is the last phase in either the JAB or Agency authorization process, it is also a reoccurring phase.
What is Con Mon or Continuous Monitoring?
This document, included in the SAP, enumerates all the rules for the assessment of the system and must be signed by both the CSP and 3PAO.
What are the Rules of Engagement?
Name two out of three of the Federal government executive branches that make up the Joint Authorization Board.
What are the Department of Homeland Security, General Services Administration, and/or Department of Defense?
This control in the RA family is all about vulnerability scanning.
What is RA-5?
All network, database, operating system, and web application vulnerability scan results are required to be submitted to the JAB or Authorizing Agency on a _______ basis.
What is monthly?
True or False - High findings in a Security Assessment Report (SAR) must be remediated or mitigated to Moderate before submission to the JAB for a P-ATO.
True.
In order to become a FedRAMP accredited 3PAO, accreditation from this organization must be obtained before final approval by the FedRAMP PMO.
What is the A2LA or American Association for Laboratory Accreditation?