# MAS-CSO-IIR — Identify Information Resources

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/mas-cso-iir

Minimum Assessment Scope (`MAS`) · group all · subset CSO
Force: MUST

## Statement

Providers MUST identify a set of information resources to assess for FedRAMP Certification that includes all information resources that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering; this set of information resources is the cloud service offering.

## Who it binds

- Providers

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

_This requirement names no JSON schema. FRC-CSO-JSN binds a provider to a schema only where a rule contains one._

## Artifacts

- {"text":"A machine readable output containing all required data of the components of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.","scope":"all","class":null,"source":"requirement"}
- {"text":"A human readable explanation of how the machine readable output is derived.","scope":"all","class":null,"source":"requirement"}
- {"text":"The code for the automated process used to generate the machine readable output.","scope":"all","class":null,"source":"requirement"}

## Timeframes

_This requirement states no deadline._

## Notifications

_This requirement demands no notification._
