CMU-CSO-CATConfiguration of Agency Tenants
allSHOULD
Providers SHOULD configure agency tenants by default to use cryptographic services that use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when such modules are available.
Who it binds
Controls whose FedRAMP guidance points at CMU (1)
Their guidance names the Cryptographic Module Use rules as a whole, not this requirement — so this is where to read from, not a mapping to this clause. Controls no KSI reaches have no page and are not listed.
Which certifications it binds
- Certification type
- 20x · Rev5
- Path
- Program · Agency
Evidence this requirement demands
- List of cryptographic modules used by default including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.
5 default artifacts owed by every FRR requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Group all, subset CSO of Cryptographic Module Use. See all obligations on /obligations or the full evidence plan on /evidence.