VER-TFR-MAVMark Accepted Vulnerabilities
allMUST
Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability.
Who it binds
Controls whose FedRAMP guidance points at VER (10)
Their guidance names the Vulnerability Evaluation and Reporting rules as a whole, not this requirement — so this is where to read from, not a mapping to this clause. Controls no KSI reaches have no page and are not listed.
Deadlines (1)
| Class | Timeframe | Statement |
|---|---|---|
| all | 192 days | Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability. |
Which certifications it binds
- Certification type
- 20x · Rev5
- Path
- Program · Agency
Evidence this requirement demands
No requirement-specific artifacts — but the defaults below still apply.
5 default artifacts owed by every FRR requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Group all, subset TFR of Vulnerability Evaluation and Reporting. See all obligations on /obligations or the full evidence plan on /evidence.