SCG-ENH-MRGMachine-Readable Guidance
allSHOULD
Providers SHOULD also provide the Secure Configuration Guide in a machine-readable format that can be used by customers or third-party tools to compare against current settings.
Who it binds
Controls whose FedRAMP guidance points at SCG (1)
Their guidance names the Secure Configuration Guide rules as a whole, not this requirement — so this is where to read from, not a mapping to this clause. Controls no KSI reaches have no page and are not listed.
Which certifications it binds
- Certification type
- 20x · Rev5
- Path
- Program · Agency
Evidence this requirement demands
- Explanation of how to access this information
- or explanation why this functionality is not available
5 default artifacts owed by every FRR requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Group all, subset ENH of Secure Configuration Guide. See all obligations on /obligations or the full evidence plan on /evidence.