FRC-CSX-MASApplication within MAS
20xSHOULD
Providers SHOULD apply ALL Key Security Indicators to ALL aspects of their cloud service offering that are within the FedRAMP Minimum Assessment Scope.
Who it binds
Which certifications it binds
- Certification type
- 20x · Rev5 — this subset states no type restriction
- Path
- Program · Agency — this subset states no path restriction
Evidence this requirement demands
No requirement-specific artifacts — but the defaults below still apply.
5 default artifacts owed by every FRR requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Group 20x, subset CSX of FedRAMP Certification. See all obligations on /obligations or the full evidence plan on /evidence.