Cloud Community of Interest FedRAMP Accelerated Feedback FedRAMP Forms, Templates and Methods of Completion June 2016 Advancing Government through Collaboration, Education and Action
Our Team Advancing Government through Collaboration, Education and Action
Templates and Methods of Completion Work Stream Team Topic Leader Jason Wong System (Superb Internet) CSP Government Integrators 3PAO Group Leader Group Leader Group Leader Group Leader Kathleen Fischer Jennifer Gray Roopangi Kadakia Kyle Hendrickson (Vencore) (Amazon Web Services) (NASA) (BRMi) Advancing Government through Collaboration, Education and Action 3
Project Overview Advancing Government through Collaboration, Education and Action
Objective and Scope Objective Collect feedback from stakeholders (CSPs, 3PAOs, Government, SIs) on the FedRAMP Forms, Templates and Methods of Completion from ACT-IAC Cloud COI members and present findings to FedRAMP PMO Scope Existing FedRAMP Templates (18 documents) Advancing Government through Collaboration, Education and Action 5
Approach Advancing Government through Collaboration, Education and Action
Approach 1. Assign group leads for each stakeholder community (CSP, 3PAO, Government, SI) 2. Develop survey 3. Solicited feedback from ACT-IAC Cloud (COI) members using web-based survey 4. Validated & synthesized feedback 5. Analyze results 6. Present findings to FedRAMP PMO 7. Deliver formal feedback to FedRAMP PMO Advancing Government through Collaboration, Education and Action 7
Survey Questions Advancing Government through Collaboration, Education and Action
The following questions were posed 1. Please rank the following [18] FedRAMP Templates in the order of importance to fully support FedRAMP Readiness, where 1 is most important and 5 is least important. 2. Please provide a brief description of any issues/challenges that you've had with the following FedRAMP templates. 3. Please rank the following [18] FedRAMP Templates in the order of importance to be refreshed, where 1 is most important and 5 is least important. 4. Please mark the preferred method of completion for the following [18] FedRAMP Templates. 5. If you selected "Other" for methods of completion, please elaborate further 6. Are you interested in working with the COI in developing a proof-of-concept (POC) for one of the above mentioned methods of completion? Advancing Government through Collaboration, Education and Action 9
Survey Results Advancing Government through Collaboration, Education and Action
Respondents • 28 responded to all questions • 7 provided specific feedback Advancing Government through Collaboration, Education and Action 11
Question 1. FedRAMP Templates in the order of importance to support FedRAMP readiness 20 1 (Most) 2 3 4 5 ( Least) 18 16 14 12 10 8 6 4 2 0 Advancing Government through Collaboration, Education and Action 12
MS Word embedded documents challenges Input should be data driven with validation Question 2. Brief description MS Word form fields limits length of input General formatting / organization issues Does not reflect latest FISMA standards Make web-based with links to sections Current format (Word/Excel) not ideal Document not valuable or not needed of any issues/challenges that you've had Not aligned with related docs Not tailored for cloud systems Need ability to import/export with FedRAMP templates Contains duplicate section Lacks grammar guidance Not prescriptive enough Other specific issues Too prescriptive Too complex N/A or None Contingency Plan Template 3 1 2 1 Controls Implementation Summary Template 3 1 1 e-Authentication Template 4 1 1 FIPS 199 Template 3 2 1 PTA & PIA Template 4 1 1 RoB Template 3 1 1 1 SSP 2 1 1 1 1 1 1 1 1 3 SAP Template 2 1 1 1 1 1 1 1 Rev. 4 Test Cases 4 1 1 1 1 1 1 FedRAMP Rev. 3 to 4 Annual Asmt. Controls Template 2 3 POA&M Template 3 1 1 1 POA&M Template Completion Guide 3 1 1 SAR 1 1 2 1 4 1 1 Template FedRAMP ATO 5 1 FedRAMP Annual Assessment. Guidance 4 1 1 Annual SAR Template 3 1 1 2 SAP for Annual Assessment 3 1 1 1 1 1 Significant Change Form 3 1 1 1 Advancing Government through Collaboration, Education and Action 13
Question 3. FedRAMP Templates in the order of importance to be refreshed (1 = most, 5 = least) 20 1 (Most) 2 3 4 5 ( Least) 18 16 14 12 10 8 6 4 2 0 Advancing Government through Collaboration, Education and Action 14
Question 4. Preferred method of completion of FedRAMP Templates 14 Web-based Word/Excel PDF Other 12 10 8 6 4 2 0 Advancing Government through Collaboration, Education and Action 15
Question 5. If you selected "Other" for methods of completion, please elaborate further. 1. .xml or other extensible or database compatible format 2. SSP, SAR, SAP all should be web-based but must be able to be exported and imported to allow for working off-line. 3. Web portal or web based form that walks you through completion process and where you can save the data as you complete it online. Also provides completion percentage. Advancing Government through Collaboration, Education and Action 16
Question 6. Are you interested in working with the COI in developing a proof-of-concept (POC) for one of the above mentioned methods of completion? 9 respondents agreed to help! Advancing Government through Collaboration, Education and Action 17
Feedback Summary Importance to determine readiness: • SSP, SAR, and SAP were ranked highest Issues/challenges with completion: • SSP, SAR, and SAP had the most comments • Some respondents felt these weren’t needed: – Controls Implementation Summary Template – e-Authentication Template – FIPS 199 Template – RoB Template – FedRAMP Rev. 3 to 4 Annual Asmt. Controls Template – Significant Change Form Advancing Government through Collaboration, Education and Action 18
Feedback Summary (continued) Importance of being refreshed: • SSP, SAR, and SAP were ranked highest Methods of Completion: • Web-based was most favored • Other methods included .xml and other extensible or database compatible formats • Ability to save and import/export data Advancing Government through Collaboration, Education and Action 19
Next Steps Advancing Government through Collaboration, Education and Action
Next steps… • Send formal feedback to FedRAMP PMO by deadline • Upcoming ACT-IAC FedRAMP Accelerated Work Streams: – June: JAB Prioritization Criteria – (Ongoing): Open Forum Advancing Government through Collaboration, Education and Action 21
Q & A Advancing Government through Collaboration, Education and Action
Recommend
More recommend