MAS-CSO-IIRIdentify Information Resources
allMUST
Providers MUST identify a set of information resources to assess for FedRAMP Certification that includes all information resources that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering; this set of information resources is the cloud service offering.
Who it binds
Controls whose FedRAMP guidance points at MAS (2)
Their guidance names the Minimum Assessment Scope rules as a whole, not this requirement — so this is where to read from, not a mapping to this clause. Controls no KSI reaches have no page and are not listed.
Which certifications it binds
- Certification type
- 20x · Rev5
- Path
- Program · Agency
Evidence this requirement demands
- A machine readable output containing all required data of the components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.
- A human readable explanation of how the machine readable output is derived.
- The code for the automated process used to generate the machine readable output.
2 authored AWS recipes produce evidence for this
- The machine-maintained component inventory — Config's recorder status and discovered-resource counts proving supported resources are tracked continuously and the list stays current without anyone editing a spreadsheet, plus Systems Manager Inventory's node and installed-application metadata for what runs inside them config-asset-inventory
- A Region-by-Region inventory of the resources that can hold information, the classification tags you asserted on them, and — where Macie exists — a sampled machine judgement about which S3 buckets actually contain sensitive data information-location-and-classification
AWS mappings are this project’s authored opinion, versioned separately from the dataset — never upstream fact.
5 default artifacts owed by every FRR requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Group all, subset CSO of Minimum Assessment Scope. See all obligations on /obligations or the full evidence plan on /evidence.