FedRAMP less granularity than NIST?

old.reddit.com / @/u/vintagenewstart, https://old.reddit.com/user/vintagenewstart

After reviewing the SAP/SAR workbook I noticed the FedRAMP methodology bundles NIST 800-53(a) granularity into larger single scope sections. Which in turn makes it less likely an organization will pass the control, even partially.

Any reasoning behind this?

Example: theoretical...

Control in NIST AC-1.a[1]....[2]....[3] all separate granularity auditing sections.

Control in FedRAMP AC-1.a[1,2,3] one single audit section.

submitted by /u/vintagenewstart
[link] [comments]

published 7 months ago




See all items from the same source