Fedramp Requirement for Security Protection Assets

old.reddit.com / @/u/PVille_89, https://old.reddit.com/user/PVille_89

As I understand, Security Protection Assets are assets which provide security functions to systems within a company's CMMC Assessment Scope and that these systems may or may not store or transmit CUI. If a company uses a cloud-based version of a Security Protection Assets, does the SPA need to be FedRamp certified (or equivalent).

submitted by /u/PVille_89
[link] [comments]

published 2 months ago




See all items from the same source