IVV-CSX-AIAAnnual Independent Assessments for 20x
20xvaries by class: a, b, c, d
The statement for this requirement varies by certification class — see the per-class deadlines below.
Who it binds
Deadlines (3)
| Class | Timeframe | Statement |
|---|---|---|
| B | 1 year | Providers with 20x Class B Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year. |
| C | 1 year | Providers with 20x Class C Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year. |
| D | 1 year | Providers with 20x Class D Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year. |
Which certifications it binds
- Certification type
- 20x · Rev5 — this subset states no type restriction
- Path
- Program · Agency — this subset states no path restriction
Evidence this requirement demands
No requirement-specific artifacts — but the defaults below still apply.
5 default artifacts owed by every FRR requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Group 20x, subset CSX of Independent Verification and Validation. See all obligations on /obligations or the full evidence plan on /evidence.