Initial publication.
Updated for annual assessment.
A virtual component.
If no risk statement from tool, set to 'No Risk Statement'.
-This is the tool-provided statement about the identified risk.
If no risk statement from tool, set to 'No Risk Statement'.
-Description of the result of the vendor check-in.
Vulnerability description
Risk statement.
Vulnerability description
Risk statement.
Explain why likelihood was adjusted.
Explain why impact was adjusted.
@@ -936,8 +936,8 @@ If the Vendor Dependent Product Name is not already defined as an individual comVulnerability description
Risk statement.
Insert text from FedRAMP template
Insert text from FedRAMP template
-Insert text from FedRAMP template
This SAP has been developed by [IA Name] and is for [an initial assessment/an annual assessment/an annual assessment and significant change assessment/a significant change assessment] of the [CSP Name], [CSO Name]. The SAP provides the goals for the assessment and details how the assessment will be conducted.
The FedRAMP-applicable laws, regulations, standards and guidance are included in the [CSO Name] SSP section – System Security Plan Approvals. Additionally, in Appendix L of the SSP, the [CSP Name] has included laws, regulations, standards, and guidance that apply specifically to this system.
Describe this web application test.
[IA Name] will ...
[IA Name] data gathering activities will ...
The sampling methodology for evidence/artifact gathering, related to controls assessment, is described in Appendix B.
[IA Name] [will/will not] ...
The Penetration Test Plan and Methodology is attached in Appendix C.
The sampling methodology for evidence/artifact gathering, related to controls assessment, is described in Appendix B.
[IA Name] [will/will not] ...
Statement about the risk identified by penetration testing.
[3PAO] attests to the accuracy of the information provided in this FedRAMP Security Assessment Report for the annual assessment
@@ -1400,7 +1400,7 @@ priority value of \"1\" represents the most important risk. \"2\" represents the
This is a statement about the identified risk as provided by the tool.
Otherwise, it is optional.
Briefly describe the interconnection details.
-FIPS 140-2 Validated Module
FIPS 140-2 Validated Module
If no, explain why. If yes, omit remarks field.
If no, explain why. If yes, omit remarks field.