RFI_-_3PAO_Requirements.docx
DOCX document 43 KB Posted
- Attached to
- RFI - FedRAMP Third Party Assessment (3PAO) Accreditation Program -Program Requirements Updates Federal contract opportunity
- Solicitation number
- RFI-XB-13-001G
About this file
3PAO Requirements Changes
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions_and_Answers_022813.docx | DOCX document | |
| RFI_-_3PAO_Requirements.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
February 15, 2013
REQUEST FOR INFORMATION (RFI):
The Program Management Office for the Federal Risk and Authorization Management Program (FedRAMP), in the Office of Citizen Services and Innovative Technology, General Services Administration, requests comments and suggestions for:
· Changes to the accreditation requirements of Third Party Assessment Organizations (3PAOs) listed in the FedRAMP 3PAO Program Requirements; and
· Changes to the 3PAO application for accreditation under the FedRAMP 3PAO Program.
NOTE:
This announcement is posted for data gathering and planning purposes only. It DOES NOT constitute a solicitation, and is not to be construed as a commitment by the Government to issue a solicitation or award a contract. The Government will not reimburse any respondent for any cost associated with information submitted in response to this RFI. The purpose of this RFI is to allow the vendor community the opportunity to provide feedback, input, and changes to FedRAMP’s 3PAO Program Requirements.
HOW TO RESPOND:
Any questions regarding this RFI should be submitted to 3PAO@FedRAMP.gov no later than 05:00 PM EDT, February 26, 2013.
Responses to this RFI shall not exceed five (5) pages and shall be received via email to 3PAO@FedRAMP.gov no later than 05:00 PM EDT, March 8, 2013. Provide a brief organization profile along with your application, including your organization’s website. Your profile will not be included in the page count for the five page response.
BACKGOUND:
The Federal Cloud Computing Initiative (FCCI), managed by GSA, developed FedRAMP as a unified, government-wide risk management program focused on securing cloud-based systems. FedRAMP established a set of security controls and templates that agencies must use in conducting security assessments of cloud-based products and services. These security assessments result in a provisional Authority to Operate (P-ATO) that agencies can leverage to authorize a CSPs service for use at their agency. By achieving a P-ATO, CSPs and agencies avoid the need to conduct redundant assessments for each agency. This “approve once, use often” approach saves much of the cost, time, and staff required to conduct individual Agency security assessments.
FedRAMP uses Third Party Assessment Organizations (3PAOs) to perform the initial and periodic assessments of Cloud Service Providers (CSPs) in the authorization process described above. 3PAOs ensure that cloud computing services and systems offered by CSPs meet specified and standardized security requirements. FedRAMP P-ATOs must include an assessment by an accredited 3PAO to ensure consistency.
FedRAMP uses a conformity assessment process to qualify 3PAOs. To become an accredited 3PAO under the FedRAMP program, 3PAOs must submit an application that demonstrates technical compliance with requirements established under FedRAMP for security assessment of cloud-based information systems, as well as organizational independence and quality management requirements based on ISO/IEC 17020:1998 for organizations performing inspections. The FedRAMP Expert Review Board (ERB), consisting only of government staff from both the National Institute of Standards and Technology (NIST) and GSA, evaluates applications.
As FedRAMP approaches Full Operational Capability (FOC), FedRAMP plans to privatize the 3PAO accreditation process. Under this approach, FedRAMP will contract with a privatized accreditation body in order to manage the 3PAO application process. With this impending change to the 3PAO application process, FedRAMP plans to update the 3PAO application as well as the 3PAO requirements documentation. The purpose of this RFI is to receive feedback, input, and suggested changes to the 3PAO application and requirements for the betterment of FedRAMP.
Review and comment on the questions below:
General:
1. Review the 3PAO Application found in Appendix A. Provide any comments or suggested additions that would enable the 3PAO program to more effectively evaluate potential 3PAOs according to the quality and organizational independence standards necessary for security authorizations?
2. Review the 3PAO Management and Technical requirements found in Appendix B. Provide any comments or suggested changes to the requirements that would improve the quality of the 3PAOs or make the requirements more clear.
3. Currently, 3PAOs must adhere to requirements based on ISO17020: 1998. When the 3PAO accreditation process is privatized, the requirements will shift to be based on ISO17020:2012. Comment on a timeframe your organization believes is reasonable for 3PAOs to become compliant with ISO17020: 2012.
Comments for Additional Questions to be Added to the 3PAO Application:
In addition to suggesting updates and/or changes to the 3PAO Application and 3PAO Requirements, review and comment on the list below of possible additions to the 3PAO application focused on experience and operational readiness.
1. Describe your organization’s experience with assessing cloud environments using a representative sample and how your organization develops representative sample sizes through appropriate methodologies based on a cloud service provider’s system.
2. How do you plan to conduct automated testing ?
3. What methodologies have you used or do you use for manual testing?
4. Identify two issues you foresee arising in the assessment of a cloud system. Describe the two problems and how your organization would address them.
5. Describe other activities or business lines your organization (and any parent organizations) performs outside of its potential role as a 3PAO.
APPENDIX A
3PAO APPLICATION
General Information
Company Name:
Company Address:
City: State: Zip Code:
Country:
Home Page URL:
FedRAMP is asking prospective assessment organizations to disclose where the company is established. One of the following blocks must be marked:
· Established in the United States;
· Established in a designated country as defined by FAR 25.003; or
· Established in a country other than the United States or a designated country as defined by FAR 25.003.
Prospective assessment organizations are advised that some agencies have requirements that restrict access to particular information to U.S. citizens only; accordingly Cloud Service Providers should consider this when selecting assessment organizations.
Designated Point of Contact for 3PAO Applicant First Name: Last Name:
Title:
Phone Number:
Email Address:
Alternative Point of Contact for 3PAO Applicant First Name: Last Name:
Title:
Phone Number:
Email Address:
Evidence of Competence and Conformance NOTE: Management and technical requirements are described in the Agreement to Adhere to the Requirements for FedRAMP Third Party Assessment Organizations (3PAO).
Please provide the following information as evidence of conformance to FedRAMP program management requirements.
ISO/IEC 17020:1998[footnoteRef:1] [1: ISO/IEC 17020:1998, General criteria for the operation of various types of bodies performing inspection, ISO/IEC 17020:1998(E); http://webstore.ansi.org/RecordDetail.aspx?sku=ISO%2fIEC+17020%3a1998]
1. Copy or description of applicant’s Management Structure and Organization Chart according to Section 6 of ISO/IEC 17020:1998. The organization chart shall clearly show the functions and lines of authority for staff within the application organization and the relationship, if any, between the FedRAMP Security Assessment functions and other activities of the application organization.
2. Documentation of the Completion and Results of the Self-Audit Against All Sections of ISO/IEC 17020:1998.
3. Copy of the applicant’s Quality System Manual according to Section 7.3 of ISO/IEC 17020:1998.
4. Cross matrix indicating where in the quality system each requirement of ISO/IEC 17020:1998 is addressed. (Note a companion requirement below in the Methodology Section of the Demonstration of Technical Capability section below.)
5. Copy of Qualifications of each of the applicant’s personnel who oversee or are key in conducting assessments according to Section 8.2 of ISO/IEC 17020:1998.
6. Copy of the Qualifications of each of the applicant’s personnel who sign or otherwise approve inspection reports and inspection certificates according to Section 13.3 of ISO/IEC 17020:1998.
7. Copy of applicant's Policies and Approach to Confidentiality according to Section 5 of ISO/IEC 17020:1998.
8. Copy of applicant’s Polices and Approach to Independence as a ‘Type A inspection body’ or ‘Type C inspection body’ according to Section 4.2 of ISO/IEC 17020:1998.
Demonstration of Technical Competence and Capability Please provide the following information as evidence to demonstrate technical competence and capability consistent with FedRAMP program technical requirements.
Please use 12 pt. font size, 8½" by 11" page size, 1 inch margin, and printed double-sided to respond to the sections below. Pages must be numbered.
1. Methodology [<= 6 pages]
For each of the following three sections, the applicant shall include with the explanations or descriptions a cross reference indicating where in the applicant's Quality System Manual the corresponding explanation or description is addressed.
a. Explain how the FedRAMP program requirements/procedures/templates, and supporting NIST publication concepts and principles are integrated in the applicant's instructions, procedures, methods, tools, etc. for security assessments.
b. Summarize the applicant's methodologies, processes, and approaches to be used in security assessment of cloud-based information system technologies and practices.
c. Summarize the applicant's methodologies and processes to generate an effective security assessment plan that, as a minimum, is consistent with the concepts and principles exemplified in NIST SP 800-53A, and describe any methodology considerations that are specific to cloud service models (IaaS/PaaS/SaaS) or deployment models (public/private/hybrid/ community).
2. System Security Plan (SSP) [FedRAMP abbreviated SSP template + <=20 pages] *
Develop a sample System Security Plan (SSP) for an applicant-selected, cloud-based information system, drawing upon a system the applicant has either previously assessed or an equivalent experimental system. The applicant selected system shall be for an SaaS cloud service model (the applicant may choose the cloud deployment model [i.e., private, public, hybrid, or community]) that is categorized as moderate-impact and, as a minimum, is capable of implementing the following FedRAMP security controls:
a. AC-2 Account Management with control enhancements (1), (2), (3), (4), (7);
b. AC-17 Remote Access with control enhancements (1), (2), (3), (4), (5), (7), (8);
c. AU-2 Auditable Events with control enhancements (3), (4);
d. CM-6 Configuration Settings with control enhancements (1), (3);
e. CP-9 Information System Backup with control enhancements (1), (3);
f. IR-4 Incident Handling with control enhancement (1);
g. RA-5 Vulnerability Scanning with control enhancements (1), (2), (3), (6), (9);
h. SC-9 Transmission Confidentiality with control enhancement (1); and
i. SI-2 Flaw Remediation with control enhancement (2).
(An abbreviated version of the FedRAMP SSP template identified as “Abbreviated 3PAO Applicant System Security Plan (SSP) Template” is available on the website www.FedRAMP.gov/3PAO for the applicant's use.)
*The applicant is requested to provide an example of an SSP to demonstrate its capability in developing and executing an effective Security Assessment Plan (SAP). Although the applicant is not being evaluated on the capability to develop SSP's, the SSP should be of sufficient detail to enable the applicant to develop a full and complete SAP.
3. Security Assessment Plan (SAP) [extended** FedRAMP assessment procedure templates + <=20 pages]
Provide a complete SAP for the system, using the applicant-developed SSP above. The plan shall include all of the security controls (a-i) described above. Refer to NIST SP 800-53A rev. 1 for guidance on developing a security assessment plan. The plan shall use the set of FedRAMP assessment procedures for security controls (a-i) above that are posted on the website www.FedRAMP.gov/3PAO and identified as "Abbreviated Set of 3PAO Applicant Assessment Procedures." The applicant's assessment procedures must be tailored to address considerations that are specific to a SaaS cloud service model and applicant-selected deployment model.
**The FedRAMP abbreviated assessment procedures are expected to be extended as appropriate to accommodate assessment of system-specific security control implementation technologies and practices described in the applicant-developed SSP.
4. Assessment Procedure Evidence and Findings Provide documented evidence and findings from simulated execution of the SAP above. Documented evidence and findings shall be recorded in the blank information blocks in the FedRAMP-provided abbreviated assessment procedure templates. The blank information blocks are located in the:
a. Assessment Case, Action Step, Evidence (assessment details and observations to support findings) column, and the Rating (NS, PS, FS, or N/A) column; and
b. Security Assessment Reporting Forms Section III Assessment Findings, "Finding" column, and Section IV Assessor Comments and Recommendations, "Assessor Comments" and "Assessor Recommendations" blocks (first two blocks).
The Assessment Evidence and Findings must include several examples of potential assessment results that range from fully satisfied to varying degrees of severity of other than satisfied that could be expected from execution of the SAP. The assessment results must include, as a minimum, two (2) examples that are judged to be of the category of "other than satisfied" (e.g., NS, PS, or N/A) for each security control (a-i) above.
The completed Assessment Procedure templates, with the documented assessment evidence and findings, shall be returned for each assessed security control and associated enhancement as supporting information for the Security Assessment Report.
5. Security Assessment Report (SAR) [FedRAMP abbreviated SAR template + <=15 pages]
Provide a complete SAR based on the assessment evidence and findings above, from simulated execution of the SAP. An abbreviated version of the FedRAMP SAR template, identified as “Abbreviated 3PAO Applicant Security Assessment Report (SAR) Template,” is available on the website www.FedRAMP.gov/3PAO for the applicant's use.
6. Experiences and Critical Success Factors [<=5 pages]
Provide descriptions of critical success factors (a minimum of five [5]), including potential resolutions, that are important to consider in providing effective security assessments. The factors may draw from experiences in the above demonstration or prior security assessment experiences.
APPENDIX B
3PAO REQUIREMENTS:
Management and Technical Requirements for 3PAOs This section defines the management and technical requirements that prospective 3PAOs must meet to be a FedRAMP Accepted Third Party Assessment Organization (3PAO).
Management Requirements
1. Conduct inspections in accordance with ISO/IEC 17020:1998. General criteria for the various types of bodies performing inspection, ISO/IEC 17020:1998 (E).[footnoteRef:2] [2: http://webstore.ansi.org/RecordDetail.aspx?sku=ISO%2fIEC+17020%3a1998]
2. Maintain an effective quality management system which addresses all requirements of ISO/IEC 17020:1998.
3. Attend all mandatory training and program update sessions. Initially, the FedRAMP PMO will conduct virtual training and meetings quarterly.
4. Maintain a training program, consistent with the ISO/IEC standards that include documented procedures and training requirements to ensure its personnel are competent to perform security assessments.
5. Conduct inspection of information security implemented in cloud-based information systems and deployment environments, including associated technology products and services implemented in those environments (for initial and continuous monitoring purposes), for conformity to program requirements.
6. Report to the FedRAMP Program Management Office, within five (5) business days of completed transaction days, any changes that materially affect its:
a. Legal, commercial, organizational, or ownership status;
b. Organization and management, including key inspection body personnel;
c. Policies or procedures;
d. Location;
e. Facilities, working environment, or other resources;
f. Accepted 3PAO authorized representative (point of contact) or alternate representative; or
g. Other such matters that may otherwise materially affect its ability to perform assessments.
7. Retain all records related to inspections according to ISO/IEC 17020:1998 and applicable federal policy.
8. Maintain technical competency to perform assessments.
9. Ensure that proprietary information is protected per client agreements.
10. Agree to abide by the requirements of the 3PAO program to achieve and maintain acceptance as a Third Party Assessment Organization, as described in Section 4.0 of the FedRAMP Third Party Assessment Organization (3PAO) Program Description.
Technical Requirements (TR)
1. Maintain knowledge, understanding, and competency in the application of the FedRAMP program security assessment standards, guidelines, and requirements. (See www.FedRAMP.gov/3PAO for a list of references.)
2. Maintain knowledge, understanding, and competency in the application and assessment of cloud-based information system-related technologies and practices.
3. Maintain knowledge and understanding in the use of supporting NIST publications/ programs. (See www.FedRAMP.gov/3PAO for a list of references.)
4. Maintain instructions, procedures, methods, worksheets, etc., relevant to the work of security assessment of cloud-based information systems that are consistent with the FedRAMP program requirements, and supporting NIST publications/programs.
5. Select assessment team personnel that collectively have the relevant knowledge, skills, and abilities for conduct of the given security assessment.
6. Prepare a security assessment plan for each assessment consistent with the FedRAMP program requirements.
7. Review the assessment plan with the cloud service provider to ensure that the security assessment plan is appropriate for the assessment; and that all necessary cloud provider information, documentation, data, artifacts, personnel, etc., for the security assessment is (or will be) available.
8. Conduct the security assessment, following the security assessment plan.
9. Prepare a security assessment report consistent with the FedRAMP program requirements.
File details come from the government source that posted it. Updated .