# MAS-CSO-FLO — Information Flows and Security Categories

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/mas-cso-flo

Minimum Assessment Scope (`MAS`) · group all · subset CSO
Force: MUST

## Statement

Providers MUST clearly identify, document, and explain information flows and security categories for ALL information resources or sets of information resources in the cloud service offering.

## Who it binds

- Providers

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

_This requirement names no JSON schema. FRC-CSO-JSN binds a provider to a schema only where a rule contains one._

## Artifacts

- {"text":"A machine readable output containing all required data of the permitted connections between components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.","scope":"all","class":null,"source":"requirement"}
- {"text":"A human readable explanation of how the machine readable output is derived.","scope":"all","class":null,"source":"requirement"}
- {"text":"The code for the automated process used to generate the machine readable output.","scope":"all","class":null,"source":"requirement"}

## Timeframes

_This requirement states no deadline._

## Notifications

_This requirement demands no notification._
