FedRAMP looking at third-party access in upcoming authorization boundary guidance

FedScoop: The Federal Risk and Authorization Management Program provided a preview of guidance it will soon issue on how internal components and external cloud service providers should document continuous monitoring compliance.

In a recent blog post, FedRAMP officials at the General Services Administration said they would soon be issuing formal guidance on CSPs’ authorization boundary — the demarcation line for security authorization responsibilities between agencies and CSPs.

FedRAMP’s Program Management Office has been examining not only the internal structures of a CSP’s data infrastructure but also the third-party partners they work with and how they access federal data and metadata.

Read article

Share