ConnectSecure

Controls

We take security, compliance, and privacy seriously. Explore our certifications, reports, and policies in one place.
⌘K

AFC-CSO-CRA

Pass
Providers MUST complete the required actions in Emergency or Emergency Test designated messages sent by FedRAMP within the timeframe included in the message.

AFC-CSO-INB

Pass
Providers MUST establish and maintain an email address to receive messages from FedRAMP; this inbox is a FedRAMP Security Inbox (FSI). • Unless otherwise notified, FedRAMP will use the listed Security Email on the Marketplace for these notifications. • If a provider establishes a new inbox in reaction to this guidance that is different from the Security Email then they must follow the AFC-CSO-NOC (Notification of Changes) rules to notify FedRAMP.

AFC-CSO-NOC

Pass
Providers MUST immediately notify FedRAMP of any changes to the email address for their FedRAMP Security Inbox.

AFC-CSO-RCV

Pass
Providers MUST receive and react to email messages from FedRAMP without disruption and without requiring additional actions from FedRAMP.

CCM-OCR-AVL

Pass
Providers MUST supply an Ongoing Certification Report to all necessary parties every 3 months, covering the entire period since the previous summary, in a consistent format that is human readable; this report MUST include high-level summaries of at least the following information: • Changes to FedRAMP Certification Data • Planned changes to FedRAMP Certification Data during at least the next 3 months • Accepted vulnerabilities • Transformative changes • Updated recommendations or best practices for security, configuration, usage, or similar aspects of the cloud service offering • A list of all agencies that are directly using the product • FedRAMP Reportable Incidents or an attestation that no such incidents occurred • Lessons learned and changes planned or made as a result of FedRAMP Reportable Incidents (if such occurred)

CCM-OCR-NRD

Pass
Providers MUST supply the target date for their next Ongoing Certification Report with other public FedRAMP Certification Data.

CCM-QTR-MTG

Pass
Providers with Class A Certifications MAY host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.

CDS-CSO-AVR

Pass
Providers with Class A Certifications SHOULD maintain a web service, available to all necessary parties, that indicates current and historical availability of core services within the cloud service offering over at least the past 30 days, including availability incidents, in both human-readable and machine-readable formats; this service SHOULD be available even if the primary cloud service offering is unavailable.

CDS-CSO-IRP

Pass
Providers MUST supply all relevant policies and procedures in the FedRAMP Certification Data, including a human-readable and machine-readable reference that explains at least the following about each included policy and procedure: • Name of policy or procedure • Name of file, document, web page, etc. • Brief summary of policy or procedure • Word count of document • Current version • Date of last update • Related FedRAMP Practices (if applicable)

CDS-CSO-PSM

Pass
Providers with Class A Certifications MAY supply per-service FedRAMP Certification materials.

CDS-CSO-PUB

Pass
Providers MUST publicly share up-to-date information about the cloud service offering in both human-readable and JSON formats, including at least the following information that is available and applicable: • FedRAMP ID • Service Model • Deployment Model • Business Category • UEI Number • Sales Contact Information • Security Contact Information • Product Website Link • Link to Product Logo • Overall Service Description • Detailed list of specific services and their security categories (see CDS-CSO-SVC (Public Service List) (Service List)) • Link to Secure Configuration Guidance • Overview of documentation supplied by the provider for the cloud service offering • Link to Trust Center landing page that includes instructions on accessing information in the trust center • Next Ongoing Certification Report date (see CCM-OCR-NRD (Next Report Date)) • Current FedRAMP Recognized independent assessment service

CDS-CSO-SVC

Pass
Providers MUST publicly share a detailed list of specific services and their security categories that are included in the cloud service offering using clear feature or service names that align with standard public marketing materials; this list MUST be complete enough for a potential customer to determine which services are and are not included in the FedRAMP Minimum Assessment Scope without requesting access to underlying FedRAMP Certification Data.

CDS-CSO-UTC

Pass
Providers MUST use a FedRAMP-compatible trust center to store and share FedRAMP Certification Data with all necessary parties.

CDS-UTC-AAD

Pass
Providers MUST notify FedRAMP within 5 business days of denying an agency access request for FedRAMP Certification Data.

CMU-CSO-CMD

Pass
Providers MUST document the cryptographic modules used in each service (or groups of services that use the same modules) where cryptographic services are used to protect federal customer data, including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.

CMU-CSO-UVM

Pass
Providers with Class A Certifications MAY use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when using cryptographic services to protect federal customer data.

CPO-CSO-MTD

Pass
Providers MUST also include the following basic metadata in their Certification Package Overview: • Name, title, and contact information of official that is responsible and accountable for the FedRAMP Certification Package • Version • Date and time of last update • Source of update

CPO-CSO-OSA

Pending
Providers seeking Class A Certification MAY also include an overall summary of their FedRAMP independent assessment in their Certification Package Overview.

CPO-CSO-OVR

Pass
Providers MUST supply a Certification Package Overview within their FedRAMP Certification Package, in both human-readable and JSON formats, that includes at least all of the information required by the following rules: • Certification Package Overview: CPO-CSO-MTD (Certification Package Overview Metadata) • Certification Data Sharing: CDS-CSO-PUB (Public Information) • Certification Data Sharing: CDS-CSO-SVC (Public Service List) • Certification Data Sharing: CDS-CSO-IRP (Include Relevant Policies) • Minimum Assessment Scope: MAS-CSO-IIR (Identify Information Resources) • Minimum Assessment Scope: MAS-CSO-FLO (Information Flows and Security Categories) • Minimum Assessment Scope: MAS-CSO-TPR (Third-Party Information Resources) • Using Cryptographic Modules: CMU-CSO-CMD (Cryptographic Module Documentation) • Independent Verification and Validation: IVV-CSO-ICP (Inclusion in Certification Package)

CPO-CSX-CPM

Pass
Providers with 20x Class A Certifications SHOULD persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 3 months.

FRC-APP-AFC

Pass
Providers MUST complete the FedRAMP Certification Application Form in full to request an initial assessment by FedRAMP.

FRC-APP-FCP

Pass
Providers MUST supply a fresh initial FedRAMP Certification Package that shows the current status of the cloud service offering as verified and validated by the provider within the previous 7 days.

FRC-APP-FIA

Pass
Providers seeking Class A Certification MAY supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.

FRC-APP-MLF

Pass
Providers MUST be listed in the FedRAMP Marketplace before applying for FedRAMP Certification, including: • FedRAMP Marketplace: MKT-CSO-MLR (Marketplace Listing Requirements), • FedRAMP Marketplace: MKT-CSO-PML (Provider Marketplace Listing Requests) • FedRAMP Marketplace: MKT-IIP-AGU (Agency Use Cases) • FedRAMP Marketplace: MKT-IIP-DCP (Demonstrating Continuous Progress)

FRC-APP-NTP

Pass
Providers MUST NOT use a third party to apply for a FedRAMP Certification on their behalf; this includes independent assessment services. • FedRAMP previously allowed independent assessment services to submit applications on behalf of providers, but this caused confusion about who was responsible for the application and the information in it. Providers should apply directly to ensure clear accountability. • Providers may use third parties to help them prepare their application and assessment materials for submission.

FRC-APP-USA

Pass
Providers MAY freshen a stale initial independent verification and validation assessment by having a FedRAMP Recognized independent assessment service review any changes between the original assessment and the current status of the cloud service offering in place of a full re-assessment, UNLESS the stale assessment is more than 9 months old.

FRC-CLA-ASF

Pass
Providers seeking a FedRAMP Class A Certification MUST have completed a certification or equivalent process, including an independent assessment if applicable, from one of the following alternative security frameworks within the past 12 months: • FedRAMP Rev5 (including FedRAMP Ready) at any historical Impact Level • SOC 2 Type II • GovRAMP at any Impact Level

FRC-CLA-EAM

Pass
Providers seeking a FedRAMP Class A Certification MUST supply the following materials from their alternative security framework assessment to all necessary parties: • SOC 2 Type II: Complete report, bridge or gap letter (if applicable), verified audit engagement documentation, estimated schedule for upcoming report, supplemental compliance evidence (if applicable) • FedRAMP Ready: Readiness Assessment Report, Security Assessment Plan, and any other materials required by FedRAMP. • GovRAMP: Readiness Assessment Report, Security Assessment Plan, and any other materials required by GovRAMP.

FRC-CLA-IVV

Pass
Providers seeking a FedRAMP Class A Certification MAY have the FedRAMP Certification Package independently verified and validated by a FedRAMP Recognized assessor before submission to FedRAMP.

FRC-CLA-MFR

Pass
Providers seeking a Class A FedRAMP Certification MUST address all rules in this FedRAMP Class A Certification subset (FRC-CLA) AND the following additional FedRAMP Class A rules; the appropriate artifacts or information mapping for all rules MUST be supplied in the FedRAMP Certification Package. • FedRAMP Certification: FRC-CSO-PKG (FedRAMP Certification Package) • FedRAMP Certification: FRC-CSO-JSN (FedRAMP JSON Schemas) • FedRAMP Certification: FRC-CSO-POP (Pick One Program Certification Type) • Minimum Assessment Scope: MAS-CSO-IIR (Identify Information Resources) • Certification Data Sharing: CDS-CSO-PUB (Public Information) • Certification Data Sharing: CDS-CSO-UTC (Use Trust Centers) • Certification Data Sharing: CDS-UTC-AAD (Agency Access Denial) • Addressing FedRAMP Communication: AFC-CSO-INB (Maintain a FedRAMP Security Inbox) • Addressing FedRAMP Communication: AFC-CSO-RCV (Receive Email Without Disruption) • Addressing FedRAMP Communication: AFC-CSO-CRA (Complete Required Actions) • Incident Evaluation and Communication: IEC-CSO-EFR (Evaluate FedRAMP Reportability) • Incident Evaluation and Communication: IEC-CSO-FIR (Final Incident Report) • Vulnerability Detection and Response: VDR-CSO-DET (Vulnerability Detection) • Collaborative Continuous Monitoring: CCM-OCR-AVL (Report Availability) • Collaborative Continuous Monitoring: CCM-OCR-NRD (Next Report Date) • Independent Verification and Validation: IVV-CSX-AIA (Annual Independent Assessments for 20x) • Key Security Indicators: KSI-CMT-LMC (Logging Changes) • Key Security Indicators: KSI-CNA-RNT (Restricting Network Traffic) • Key Security Indicators: KSI-CED-RAT (Reviewing All Training) • Key Security Indicators: KSI-IAM-AAM (Automating Account Management) • Key Security Indicators: KSI-IAM-APM (Adopting Passwordless Methods) • Key Security Indicators: KSI-INR-RIR (Reviewing Incident Response Procedures) • Key Security Indicators: KSI-SVC-SIN (Securing Information)

FRC-CLA-OFR

Pass
Providers seeking a Class A FedRAMP Certification MAY address the following additional optional FedRAMP Class A rules (if applicable): • Collaborative Continuous Monitoring: CCM-QTR-MTG (Quarterly Review Meeting) • Certification Data Sharing: CDS-CSO-PSM (Per-Service Certification Materials) • Cryptographic Module Use: CMU-CSO-UVM (Using Validated Cryptographic Modules) • FedRAMP Certification: FRC-APP-FIA (Fresh Independent Assessment) • Independent Verification and Validation: IVV-CSO-FIA (FedRAMP Independent Assessments) • Security Decision Record: SDR-CSX-KMT (Key Security Indicator Metrics) • Vulnerability Evaluation and Reporting: VER-TFR-IRI (Internet-Reachable Incidents) • Vulnerability Evaluation and Reporting: VER-TFR-MRH (Historical Activity) • Vulnerability Evaluation and Reporting: VER-TFR-NRI (Non-Internet-Reachable Incidents)

FRC-CLA-RFR

Pass
Providers seeking a Class A FedRAMP Certification SHOULD address the following additional recommended FedRAMP Class A rules (if applicable): • Certification Data Sharing: CDS-CSO-AVR (Availability Reporting) • Certification Package Overview: CPO-CSF-CPM (Certification Package Maintenance for Rev5) • Certification Package Overview: CPO-CSX-CPM (Certification Package Maintenance for 20x) • Incident Evaluation and Communication: IEC-CSO-IIR (Initial Incident Report) • Incident Evaluation and Communication: IEC-CSO-OIR (Ongoing Incident Reports) • Vulnerability Detection and Response: VDR-TFR-MVX (Persistent Machine Verification and Validation for 20x) • Vulnerability Detection and Response: VDR-TFR-PCD (Persistently Complete Detection) • Vulnerability Detection and Response: VDR-TFR-PDD (Persistent Drift Detection) • Vulnerability Detection and Response: VDR-TFR-PSD (Persistent Sample Detection) • Vulnerability Detection and Response: VDR-TFR-PVR (Mitigation and Remediation Expectations) • Vulnerability Evaluation and Reporting: VER-TFR-EVU (Evaluate Vulnerabilities Quickly)

FRC-CSO-FCP

Pass
Providers MUST identify a target FedRAMP Certification Profile and apply all relevant FedRAMP Practices to the cloud service offering.

FRC-CSO-JSN

Pass
Providers MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule.

FRC-CSO-MRA

Pass
Providers MUST maintain responsibility and accountability for the accuracy and completeness of all information in the FedRAMP Certification Package, especially when they engage a third party (such as an independent assessor, advisory service, or external tools) to supply information on their behalf.

FRC-CSO-PKG

Pass
Providers seeking a Certification MUST supply a complete FedRAMP Certification Package to FedRAMP for initial certification; the FedRAMP Certification Package MUST include at least the following information: • Information about the Cloud Service Offering following CPO-CSO-OVR (Overview of the Cloud Service Offering) • Implementation, Validation, and Assessment information for each relevant FedRAMP requirement/control/ksi as defined in SDR-CSO-FRR (FedRAMP Rules) • A real or example Ongoing Certification Report following CCM-OCR-AVL (Report Availability)

FRC-CSO-POP

Pass
Providers MUST NOT seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering; pick one type.

FRC-CSX-MOT

Pass
Providers seeking 20x Class A Certification MAY supply historical metrics for Key Security Indicators.

FRC-CSX-VVK

Pass
Providers seeking 20x Class A Certification MAY implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators.

FRC-CSX-VVR

Pass
Providers seeking 20x Class A Certification MAY implement automated methods to persistently verify and validate the accuracy and completeness of the Security Decision Record for FedRAMP rules when applicable.

IEC-CSO-DPR

Pass
Providers MUST treat FedRAMP Reportable Incidents as if they have a Potential Agency Impact N-rating (PAIN) of 5 UNLESS they promptly estimate the PAIN rating following the rule in IEC-CSO-EFI (Estimate Federal Impact).

IEC-CSO-EFI

Pass
Providers SHOULD promptly estimate the likely adverse impact of an incident on agency customers to assign a Potential Agency Impact N-rating; this step is called Incident Rating. • N1 for a likely minimal customer effect on 1 or more agencies. • N2 for a likely narrow customer effect on 1 or more agencies. • N3 for a likely disruptive customer effect on 1 agency. • N4 for a likely debilitating customer effect on 1 agency or a likely disruptive customer effect on more than 1 agency. • N5 for a likely debilitating customer effect on more than 1 agency.

IEC-CSO-EFR

Pass
Providers MUST promptly evaluate incidents to determine if they affect confidentiality or integrity of federal customer data or are likely to affect confidentiality or integrity of federal customer data; such incidents are FedRAMP Reportable Incidents and must be reported following the FedRAMP Incident Evaluation and Communication rules.

IEC-CSO-FIR

Pass
Providers with Class A Certifications MUST responsibly notify all affected parties by providing a Final Incident Report once the incident has been resolved and recovery is complete, including final updates to all previously reported information. PAIN Rating Timeframes: • PAIN 1: 3 business days • PAIN 2: 3 business days • PAIN 3: 3 business days • PAIN 4: 3 business days • PAIN 5: 3 business days

IEC-CSO-IIR

Pass
Providers with Class A Certifications SHOULD responsibly notify all affected parties after identifying FedRAMP Reportable Incidents by providing an Initial Incident Report with as much of the following information that is available at the time of reporting and/or the current relevant status for each item: • Contact information for the federal incident response [ coordinator ] • Provider's internally assigned tracking identifier • Description of the incident • Timeline of the incident, including start time, time and source of detection, time of completed FedRAMP Reportable Incident evaluation, and other major incident milestones determined by the provider • Historically and currently estimated Potential Agency Impact N-rating (PAIN) of the incident, including an explanation of the evaluation following the requirements in IEC-CSO-EFI (Estimate Federal Impact) (if applicable) • Functional impact to federal agency customers (include impact to confidentiality and/or integrity and the impacted federal customer data types) • Estimated recovery plan, milestones, and timelines • List of likely affected customer agencies PAIN Rating Timeframes: • PAIN 1: 1 business day • PAIN 2: 1 business day • PAIN 3: 6 hours • PAIN 4: 6 hours • PAIN 5: 6 hours

IEC-CSO-OIR

Pass
Providers with Class A Certifications SHOULD responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item: • Observed incident activity • Indicators of compromise • Related Common Vulnerabilities and Exposures (CVE) identifier (if applicable) • Root cause • Response and recovery activities PAIN Rating Timeframes: • PAIN 1: 1 business day • PAIN 2: 1 business day • PAIN 3: 1 business day • PAIN 4: 1 business day • PAIN 5: 1 business day

IVV-CSO-FIA

Pass
Providers with Class A Certifications MAY persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.

IVV-CSO-ICP

Pass
Providers MUST supply the results of FedRAMP independent assessments in their FedRAMP Certification Package without inappropriate modification. • Inappropriate modification in this context means changing the underlying intent/etc. of the content provided by the independent assessment service - the content itself may be modified for presentation, formatting, etc. as needed. • This rule is related to IVV-IAS-VIP (Verify Inclusion in Certification Package).

IVV-CSX-AIA

Pass
Providers with 20x Class A Certifications MUST meet the expectations of their underlying alternative security framework as part of their persistent independent verification and validation assessment.

KSI-CED-RAT

Pending
The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.

KSI-CMT-LMC

Pending
Modifications to the cloud service offering are logged and monitored.

KSI-CNA-RNT

Pass
Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.

KSI-IAM-AAM

Pass
The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.

KSI-IAM-APM

Pass
Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.

KSI-INR-RIR

Pass
The effectiveness of documented incident response procedures is persistently reviewed.

KSI-SVC-SIN

Pass
Information is encrypted or otherwise secured from unwanted access or modification.

MAS-CSO-FLO

Pass
Providers MUST clearly identify, document, and explain information flows and security categories for ALL information resources or sets of information resources in the cloud service offering.

MAS-CSO-IIR

Pass
Providers MUST identify a set of information resources to assess for FedRAMP Certification that includes all information resources that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering; this set of information resources is the cloud service offering. • Certain categories of cloud computing products and services are specified as entirely outside the scope of FedRAMP by the Director of the Office of Management and Budget. All such products and services are therefore not included in the cloud service offering for FedRAMP. For more, see https://fedramp.gov/scope. • Software produced by cloud service providers that is delivered separately for installation on agency systems and not operated in a shared responsibility model (typically including agents, application clients, mobile applications, etc. that are not fully managed by the cloud service provider) is not a cloud computing product or service and is entirely outside the scope of FedRAMP under the FedRAMP Certification Act. All such software is therefore not included in the cloud service offering for FedRAMP. For more, see https://fedramp.gov/scope. • All aspects of the cloud service offering are determined and maintained by the cloud service provider in accordance with related FedRAMP Certification rules and documented by the cloud service provider in their FedRAMP Certification Package.

MAS-CSO-TPR

Pass
Providers MUST address the potential impact to federal customer data from third-party information resources used by the cloud service offering, ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES, by documenting the following information about each applicable third-party information resource: • General usage and configuration • Explanation or justification for use • Mitigation measures in place to reduce the potential impact to federal customer data • Compensating controls in place to reduce the potential impact to federal customer data

MKT-CSO-MLR

Pass
Providers MUST address at least these FedRAMP rules to apply for a new FedRAMP Marketplace listing OR to request updates to an existing listing: • Certification Data Sharing: CDS-CSO-PUB (Public Information)

MKT-CSO-PML

Pass
Providers MUST notify FedRAMP using the FedRAMP Marketplace Providing Listing Request Form to request a listing in the FedRAMP Marketplace.

MKT-IIP-AGU

Pass
Providers MUST demonstrate that a cloud service offering is intended for one of the following use cases: • Direct Use: The product will be used directly by agency customers for integration into a federal information system that falls within the scope of 44 USC § 3506 and will receive an agency Authorization to Operate. • Indirect Use: The product will be included as a third-party information resource in other cloud service offerings that are directly used by agency customers.

MKT-IIP-DCP

Pass
Providers MUST demonstrate continuous progress towards a FedRAMP Certification, documented in their Trust Center or website and updated at least quarterly; progress is measured by the provider against documented goals and milestones.

MKT-IIP-DLA

Pass
Providers MUST demonstrate that an assessment for a FedRAMP Certification Class B, C, or D has been scheduled within 2 years of initial listing in the Initial Implementation Phase.

SDR-CSO-FRR

Pass
Providers MUST supply a Security Decision Record, in both human-readable and JSON formats, that includes at least all of the following information for each applicable FedRAMP rule: • Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule. • Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official. • Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official. • Independent verification. • Independent validation. • Any responses or clarifications to the comments in the independent verification or validation. • Rule-specific artifacts (if applicable).

SDR-CSX-KMT

Pass
Providers with 20x Class A Certifications MAY also include historical metrics in their Security Decision Record.

VDR-CSO-DET

Pass
Providers MUST systematically, persistently, and promptly discover and identify vulnerabilities within their cloud service offering using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities; this process is called vulnerability detection. Vulnerability detection includes persistently verifying and validating that information resources and processes are operating as intended and documented for FedRAMP Practices. • FedRAMP's vulnerability detection (and response) rules are intended to set modern expectations for maintaining the security of a cloud service. Historical FedRAMP guidance on vulnerability scanning or continuous monitoring generally focused only on CVE-type vulnerabilities while leaving other types of vulnerabilities and exposures unaddressed. • Providers are encouraged to leverage their existing holistic security review, architecture review, and similar processes to meet these requirements. FedRAMP strongly discourages providers from implementing separate vulnerability detection and response processes for FedRAMP reporting that are operated by independent compliance branches unless these processes are consuming data directly from the areas of the cloud service that actively maintain it.

VDR-TFR-MVX

Pass
Providers of FedRAMP 20x Class A offerings SHOULD verify and validate the status of machine-based information resources at least once every month.

VDR-TFR-PCD

Pending
Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.

VDR-TFR-PDD

Pending
Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 3 months.

VDR-TFR-PSD

Pending
Providers with Class A Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 14 days.

VDR-TFR-PVR

Pending
Providers with Class A Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely [ exploitability ]. PAIN Rating Timeframes: • PAIN 1: No specific timeframe defined • PAIN 2: 96 days (Internet-Reachable Vulnerability + Likely Exploitable Vulnerability); 160 days (Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability); 192 days (Not Likely Exploitable Vulnerability) • PAIN 3: 32 days (Internet-Reachable Vulnerability + Likely Exploitable Vulnerability); 64 days (Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability); 192 days (Not Likely Exploitable Vulnerability) • PAIN 4: 8 days (Internet-Reachable Vulnerability + Likely Exploitable Vulnerability); 32 days (Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability); 64 days (Not Likely Exploitable Vulnerability) • PAIN 5: 4 days (Internet-Reachable Vulnerability + Likely Exploitable Vulnerability); 8 days (Not Internet-Reachable Vulnerability + Likely Exploitable Vulnerability); 32 days (Not Likely Exploitable Vulnerability)

VER-EVA-EPA

Pass
Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to estimate the potential agency impact of exploitation on government customers AND assign one of the following Potential Agency Impact N-ratings (PAIN): • N1: Exploitation could be expected to have minimal customer effects on one or more agencies that use the cloud service offering. • N2: Exploitation could be expected to have narrow customer effects on one or more agencies that use the cloud service offering. • N3: Exploitation could be expected to have a disruptive customer effect on one agency that uses the cloud service offering. • N4: Exploitation could be expected to have a debilitating customer effect on one agency that uses the cloud service offering OR a disruptive customer effect on more than one federal agency that uses the cloud service offering. • N5: Exploitation could be expected to have a debilitating customer effect on more than one agency that uses the cloud service offering.

VER-TFR-EVU

Pass
Providers with Class A Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 14 days of detection.

VER-TFR-IRI

Pass
Providers with Class A Certifications MAY treat internet-reachable likely exploitable vulnerabilities where Potential Agency Impact N-rating > 3 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N3 or below.

VER-TFR-MRH

Pass
Providers with Class A Certifications MAY make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information MAY be updated persistently, at least once every month.

VER-TFR-NRI

Pass
Providers with Class A Certifications MAY treat likely exploitable vulnerabilities that are NOT internet-reachable where Potential Agency Impact N-rating = 5 as a FedRAMP Reportable Incident until they are partially mitigated vulnerabilities at N4 or below.