{"id":1436,"date":"2012-05-08T08:50:00","date_gmt":"2012-05-08T08:50:00","guid":{"rendered":"http:\/\/cloudcomputing.sys-con.com\/node\/2271981"},"modified":"2012-05-08T08:50:00","modified_gmt":"2012-05-08T08:50:00","slug":"fedramp-releases-updated-security-assessment-plan-templates","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/fedramp-releases-updated-security-assessment-plan-templates\/","title":{"rendered":"FedRAMP Releases Updated Security Assessment Plan Templates"},"content":{"rendered":"<p><\/p>\n<div class=\"MsoNormal\">\nLast week the GSA FedRAMP Program Office released the latest version of the cloud computing <a href=\"http:\/\/www.slideshare.net\/kvjacksn\/sap-template-050312\" >Security Assessment Plan (SAR) <\/a>template.&nbsp; This document is the most recent step toward the Federal governments goal of establishing FedRAMP initial operating Capability by June 2012.<\/div>\n<div class=\"MsoNormal\">\n<\/div>\n<div class=\"MsoNormal\">\nThe Federal Risk Authorization Management Program (FedRAMP) is<br \/>\na government-wide program that provides a standardized approach to security assessment,<br \/>\nauthorization, and continuous monitoring for Cloud Service Providers (CSP).<br \/>\nTesting security controls is an integral part of the FedRAMP security<br \/>\nauthorization requirements and enables Federal Agencies to use the findings<br \/>\nthat result from the tests to make risk-based decisions. Providing a plan for<br \/>\nsecurity control ensures that the process runs smoothly. This document has been designed for CSP Third-Party<br \/>\nIndependent Assessors (3PAOs) to use for planning security testing of CSPs.<br \/>\nOnce filled out, this document constitutes a plan for testing. Actual findings<br \/>\nfrom the tests are to be recorded in FedRAMP security test procedure workbooks<br \/>\nand a Security Assessment Report (SAR). <\/div>\n<p>\nThis release also includes templates for:<\/p>\n<ul>\n<li style=\"color: blue;\"><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/information-technology-contingency-plan-template\" ><span style=\"font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 12pt;\">Information Technology Contingency Plan&nbsp;<\/span><\/a><\/li>\n<li style=\"color: blue;\"><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/control-implementation-summary-cis-template\" ><span style=\"font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 12pt;\">Control Implementation Summary (CIS) <\/span><\/a><\/li>\n<li style=\"color: blue;\"><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/e-authentication-template-050212\" ><span style=\"font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 12pt;\">eAuthentication <\/span><\/a><\/li>\n<li style=\"color: blue;\"><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/fed-ramp-poam-template-050212\" ><span style=\"font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 12pt;\">Plan of Action and Milestones (POA&amp;M)<\/span><\/a><\/li>\n<li style=\"color: blue;\"><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/fed-ramp-rob-050212\" ><span style=\"font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 12pt;\">Rules of Behavior<\/span><\/a><\/li>\n<li style=\"color: blue;\"><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/pta-and-pia-050212-12840957\" ><span style=\"font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 12pt;\">Privacy Threshold Analysis and Privacy Impact Assessment<\/span><\/a><\/li>\n<li><span style=\"color: black; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 12pt;\"><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/sap-template-050312-12840878\" >Security Assessment Plan<\/a>; and<\/span><\/li>\n<li style=\"color: blue;\"><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/fedramp-system-security-plan-template-12840974\" ><span style=\"font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; font-size: 12pt;\">FedRAMP System Security Plan<\/span><\/a><\/li>\n<\/ul>\n<div>\n<a class=\"addthis_button\" expr:addthis:title=\"data:post.title\" expr:addthis:url=\"data:post.url\" href=\"http:\/\/www.blogger.com\/blogger.g?blogID=1864015076802946059&amp;pli=1\"><img loading=\"lazy\" decoding=\"async\" alt=\"Bookmark and Share\" height=\"16\" src=\"http:\/\/s7.addthis.com\/static\/btn\/v2\/lg-share-en.gif\" style=\"border: 0;\" width=\"125\" \/><\/a><br \/>\n<script type=\"text\/javascript\">\nvar addthis_config = {\"data_track_clickback\":true};\n<\/script><br \/>\n<script src=\"http:\/\/s7.addthis.com\/js\/250\/addthis_widget.js#username=kvjacksn\" type=\"text\/javascript\">\n<\/script><\/div>\n<p><a href=\"http:\/\/feeds.feedburner.com\/~r\/CloudMusingsOnForbes\/~6\/1\" ><img decoding=\"async\" alt=\"Cloud Musings on Forbes\" src=\"http:\/\/feeds.feedburner.com\/CloudMusingsOnForbes.1.gif\" style=\"border: 0;\" \/><\/a><\/p>\n<p>\n( <i> Thank you. If you enjoyed this article<\/i>, <a href=\"http:\/\/twurl.nl\/xwd37w\"><i>get free updates by email or RSS<\/i><\/a><i> &#8211; KLJ <\/i>)<\/p>\n<p><script src=\"http:\/\/pmetrics.performancing.com\/js\" type=\"text\/javascript\">\n<\/script><br \/>\n<script type=\"text\/javascript\">\n<!--\nclicky.init(9899);\n\/\/ -->\n<\/script><\/p>\n<p><script type=\"text\/javascript\">\n<!--\nvar gaJsHost = ((\"https:\" == document.location.protocol) ? \"https:\/\/ssl.\" : \"http:\/\/www.\");\ndocument.write(unescape(\"%3Cscript src='\" + gaJsHost + \"google-analytics.com\/ga.js' type='text\/javascript'%3E%3C\/script%3E\"));\n\/\/ -->\n<\/script><br \/>\n<script type=\"text\/javascript\">\n<!--\ntry {\nvar pageTracker = _gat._getTracker(\"UA-5213477-9\");\npageTracker._trackPageview();\n} catch(err) {}\n\/\/ -->\n<\/script><\/p>\n<div class=\"blogger-post-footer\">Follow me at http:\/\/Twitter.com\/Kevin_Jackson<img width='1' height='1' src='https:\/\/blogger.googleusercontent.com\/tracker\/1864015076802946059-4662255212813639274?l=kevinljackson.blogspot.com' alt='' \/><\/div>\n<p><a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/A1mDGT1LJyrmi8TW9hOpsSyBJXk\/0\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/A1mDGT1LJyrmi8TW9hOpsSyBJXk\/0\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><br \/>\n<a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/A1mDGT1LJyrmi8TW9hOpsSyBJXk\/1\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/A1mDGT1LJyrmi8TW9hOpsSyBJXk\/1\/di\" border=\"0\" ismap=\"true\"><\/img><\/a><\/p>\n<div class=\"feedflare\">\n<a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:yIl2AUoC8zA\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=yIl2AUoC8zA\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:qj6IDK7rITs\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=qj6IDK7rITs\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:63t7Ie-LG7Y\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=63t7Ie-LG7Y\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:dnMXMwOfBR0\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=dnMXMwOfBR0\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:F7zBnMyn0Lo\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?i=3UCMXhUcoII:Ba71uO0mURs:F7zBnMyn0Lo\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:V_sGLiPBpWU\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?i=3UCMXhUcoII:Ba71uO0mURs:V_sGLiPBpWU\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:l6gmwiTKsz0\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=l6gmwiTKsz0\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:gIN9vFwOqvQ\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?i=3UCMXhUcoII:Ba71uO0mURs:gIN9vFwOqvQ\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:TzevzKxY174\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=TzevzKxY174\" border=\"0\"><\/img><\/a>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/kevinljackson\/~4\/3UCMXhUcoII\" height=\"1\" width=\"1\"\/><\/p>\n<p><a href=\"http:\/\/cloudcomputing.sys-con.com\/node\/2271981\" >read more<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><\/p>\n<div>\nLast week the GSA FedRAMP Program Office released the latest version of the cloud computing <a href=\"http:\/\/www.slideshare.net\/kvjacksn\/sap-template-050312\" target=\"_blank\">Security Assessment Plan (SAR) <\/a>template.&nbsp; This document is the most recent step toward the Federal governments goal of establishing FedRAMP initial operating Capability by June 2012.<\/div>\n<div>\n<\/div>\n<div>\nThe Federal Risk Authorization Management Program (FedRAMP) is<br \/>\na government-wide program that provides a standardized approach to security assessment,<br \/>\nauthorization, and continuous monitoring for Cloud Service Providers (CSP).<br \/>\nTesting security controls is an integral part of the FedRAMP security<br \/>\nauthorization requirements and enables Federal Agencies to use the findings<br \/>\nthat result from the tests to make risk-based decisions. Providing a plan for<br \/>\nsecurity control ensures that the process runs smoothly. This document has been designed for CSP Third-Party<br \/>\nIndependent Assessors (3PAOs) to use for planning security testing of CSPs.<br \/>\nOnce filled out, this document constitutes a plan for testing. Actual findings<br \/>\nfrom the tests are to be recorded in FedRAMP security test procedure workbooks<br \/>\nand a Security Assessment Report (SAR). <\/div>\n<p>\nThis release also includes templates for:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/information-technology-contingency-plan-template\" target=\"_blank\"><span>Information Technology Contingency Plan&nbsp;<\/span><\/a><\/li>\n<li><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/control-implementation-summary-cis-template\" target=\"_blank\"><span>Control Implementation Summary (CIS) <\/span><\/a><\/li>\n<li><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/e-authentication-template-050212\" target=\"_blank\"><span>eAuthentication <\/span><\/a><\/li>\n<li><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/fed-ramp-poam-template-050212\" target=\"_blank\"><span>Plan of Action and Milestones (POA&amp;M)<\/span><\/a><\/li>\n<li><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/fed-ramp-rob-050212\" target=\"_blank\"><span>Rules of Behavior<\/span><\/a><\/li>\n<li><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/pta-and-pia-050212-12840957\" target=\"_blank\"><span>Privacy Threshold Analysis and Privacy Impact Assessment<\/span><\/a><\/li>\n<li><span><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/sap-template-050312-12840878\" target=\"_blank\">Security Assessment Plan<\/a>; and<\/span><\/li>\n<li><a href=\"http:\/\/www.slideshare.net\/kvjacksn\/fedramp-system-security-plan-template-12840974\" target=\"_blank\"><span>FedRAMP System Security Plan<\/span><\/a><\/li>\n<\/ul>\n<div>\n<a href=\"http:\/\/www.blogger.com\/blogger.g?blogID=1864015076802946059&amp;pli=1\"><img loading=\"lazy\" decoding=\"async\" alt=\"Bookmark and Share\" height=\"16\" src=\"http:\/\/s7.addthis.com\/static\/btn\/v2\/lg-share-en.gif\" style=\"border: 0\" width=\"125\" \/><\/a><\/p>\n<\/div>\n<p><a href=\"http:\/\/feeds.feedburner.com\/~r\/CloudMusingsOnForbes\/~6\/1\" target=\"_blank\"><img decoding=\"async\" alt=\"Cloud Musings on Forbes\" src=\"http:\/\/feeds.feedburner.com\/CloudMusingsOnForbes.1.gif\" style=\"border: 0\" \/><\/a><\/p>\n<p>\n( <i> Thank you. If you enjoyed this article<\/i>, <a href=\"http:\/\/twurl.nl\/xwd37w\"><i>get free updates by email or RSS<\/i><\/a><i> &#8211; KLJ <\/i>)<\/p>\n<div>Follow me at http:\/\/Twitter.com\/Kevin_Jackson<img loading=\"lazy\" decoding=\"async\" width=\"1\" height=\"1\" src=\"https:\/\/blogger.googleusercontent.com\/tracker\/1864015076802946059-4662255212813639274?l=kevinljackson.blogspot.com\" alt=\"\" \/><\/div>\n<p><a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/A1mDGT1LJyrmi8TW9hOpsSyBJXk\/0\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/A1mDGT1LJyrmi8TW9hOpsSyBJXk\/0\/di\" border=\"0\"><\/img><\/a><br \/>\n<a href=\"http:\/\/feedads.g.doubleclick.net\/~a\/A1mDGT1LJyrmi8TW9hOpsSyBJXk\/1\/da\"><img decoding=\"async\" src=\"http:\/\/feedads.g.doubleclick.net\/~a\/A1mDGT1LJyrmi8TW9hOpsSyBJXk\/1\/di\" border=\"0\"><\/img><\/a><\/p>\n<div>\n<a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:yIl2AUoC8zA\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=yIl2AUoC8zA\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:qj6IDK7rITs\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=qj6IDK7rITs\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:63t7Ie-LG7Y\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=63t7Ie-LG7Y\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:dnMXMwOfBR0\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=dnMXMwOfBR0\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:F7zBnMyn0Lo\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?i=3UCMXhUcoII:Ba71uO0mURs:F7zBnMyn0Lo\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:V_sGLiPBpWU\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?i=3UCMXhUcoII:Ba71uO0mURs:V_sGLiPBpWU\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:l6gmwiTKsz0\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=l6gmwiTKsz0\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:gIN9vFwOqvQ\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?i=3UCMXhUcoII:Ba71uO0mURs:gIN9vFwOqvQ\" border=\"0\"><\/img><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?a=3UCMXhUcoII:Ba71uO0mURs:TzevzKxY174\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/kevinljackson?d=TzevzKxY174\" border=\"0\"><\/img><\/a>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~r\/kevinljackson\/~4\/3UCMXhUcoII\" height=\"1\" width=\"1\" \/><\/p>\n<p><a href=\"http:\/\/cloudcomputing.sys-con.com\/node\/2271981\" target=\"_blank\">read more<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-1436","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/1436","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=1436"}],"version-history":[{"count":0,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/1436\/revisions"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=1436"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=1436"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=1436"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}