cloud-gov / product

Program-level artifacts, workflow and issues for cloud.gov
Creative Commons Zero v1.0 Universal
29 stars 15 forks source link

Add Rev 4 controls to Rev5 CIS / CRM (100% complete) and perform peer review #2856

Closed seanmbazemore closed 4 months ago

seanmbazemore commented 6 months ago

In order to comply with National Institutes of Standards and Technology (NIST) Special Publication (SP) 800-53 (SP 800-53), Security and Privacy Controls for Federal Information Systems and Organizations, Revision 5 FedRAMP's has mandated a CSP Rev4 to Rev 5 Baseline Transition Plan that Signed May 30, 2023 and due September 1, 2023 and October 1, 2023. Cloud.gov lacked the resources to comply with a 90 day mandate and agreed to deliver the documentation no later than (NLT) March 17, 2024 which includes:

Next steps:

Divide the Delta Controls needed to be added to template among Assurance group to do initial evaluation and add them to CIS/CRM

Meet as group to adjudicate all delta controls in template

Chiakao commented 6 months ago

Completed peer review