The file's text, extracted by GovTribe without its formatting.
U.S. General Services Administration [LiSaaS Solution Name] Low Impact Software-as-a-Service (LiSaaS) Solution Profile [Date] [LiSaaS Solution Name] Profile
Version 2/7/2023
Profile Instructions: For each section of the profile, follow the blue italicized instructions contained in each box. After the sections have been completed, remove the instruction boxes (including this box) and any examples provided in the tables.
[SaaS Solution Name] Overview:
Instruction: Summarize the SaaS Solution being provided. Convey the who, what, when, where, and how with regards to the service function and purpose across all users.
Infrastructure Overview:
Instruction: Summarize the Vendor infrastructure(s) the SaaS solution leverages. For example, “The system is built in Amazon AWS with a multi-region architecture deployed in AWS East and AWS West for high availability."
Additionally, in the following table, identify whether the infrastructure services and the service used are FedRAMP or CISO authorized. (Note: GSA can provide a list of CISO authorized Infrastructure-as-a-Service (IaaS) services per provider as needed.)
Leveraged Vendor Infrastructure Services
| Service Name |
| FedRAMP Authorized / CISO Authorized |
| AWS EC2 (example) |
| FedRAMP Authorized |
| AWS Inspector (example) |
| FedRAMP Authorized |
| AWS GuardDuty (example) |
| CISO Authorized |
Instruction: In the following table, identify the Vendor SaaS integration(s) used to provide the LiSaaS offering. Identify whether the infrastructure is FedRAMP authorized. If there are no Vendor SaaS integrations, enter “Not applicable – no vendor SaaS integrations.”
Vendor SaaS Integration(s)
| SaaS Name |
| FedRAMP Authorized |
| Github (example) |
| FedRAMP Authorized |
| OpsGenie (example) |
| Not FedRAMP Authorized |
[SaaS Solution Name] Solution Summary Instruction: In the following table, provide an overview of the LiSaaS solution, including the type of data and the risk level based on the sensitivity of the data, authorization capability, MFA capability, identify if the following capabilities exist-- completed ICAM Portfolio review, audit/logging capability, and encryption capabilities in storage and at rest.
| Data Description and Sensitivity |
| [Describe] |
| Authorization Capability |
| [Describe how accounts and roles are managed (e.g., add/remove), authorized (e.g., least privilege) and audited (e.g., monitored)]. |
| Multi-factor Authentication Capability(ies) |
| [Describe the types of users of the system. For example: |
· GSA users (@gsa.gov) only
· Other federal agency customers (@agency.gov)
· Vendors
· Public] [Note: Perform an ICAM Portfolio review (see CIO 2183.1) to determine the GSA authentication service(s) to integrate with. The GSA IT Program Manager or GSA Information System Security Officer should complete this form for an evaluation.]
| ICAM Portfolio Review Completed |
| Choose an item. |
| Audit Logging Capability |
| Choose an item. |
| Encryption in Transit Capability |
| Choose an item. |
| Encryption in Storage Capability |
| Choose an item. |
Users
| User Type(s) |
| Included? |
| Estimated Number |
| Authentication Service |
| GSA Users |
| Choose an item. |
| Other federal agency users |
| Choose an item. |
[SaaS Solution Name] Connection Type(s)
(If additional rows are needed, add them to the end of this table)
| Connection Type (to GSA) |
| Choose an item. |
| Is API over HTTPS? |
| Choose an item. |
| API Connection Security |
| Describe. |
| API Connection Type |
| Describe. |
image1.png image2.png