FedRAMP FedRAMP Third-Party Assessment & Supply Chain 1 — Questions and Answers
Question 1: What is the primary role of a Third-Party Assessment Organization (3PAO) in the FedRAMP authorization process?
- To independently test and evaluate a CSP's security controls and produce a Security Assessment Report (Correct answer)
- To grant the Authorization to Operate to the cloud service provider
- To develop the System Security Plan on behalf of the CSP
- To monitor the CSP's compliance after authorization is granted
Correct answer: To independently test and evaluate a CSP's security controls and produce a Security Assessment Report
A 3PAO independently assesses the CSP's security controls and produces the Security Assessment Report (SAR) used in the authorization decision.
Question 2: Which organization accredits Third-Party Assessment Organizations (3PAOs) to perform FedRAMP assessments?
- American Association for Laboratory Accreditation (A2LA) (Correct answer)
- National Institute of Standards and Technology (NIST)
- Department of Homeland Security (DHS)
- General Services Administration (GSA)
Correct answer: American Association for Laboratory Accreditation (A2LA)
A2LA (American Association for Laboratory Accreditation) is the accreditation body that certifies 3PAOs to perform FedRAMP security assessments.
Question 3: What document does a 3PAO produce that outlines the planned scope, methodology, and schedule for a FedRAMP security assessment?
- Security Assessment Plan (SAP) (Correct answer)
- System Security Plan (SSP)
- Security Assessment Report (SAR)
- Plan of Action and Milestones (POA&M)
Correct answer: Security Assessment Plan (SAP)
The Security Assessment Plan (SAP) describes how the 3PAO will conduct the assessment, including test cases, scope, and timeline.
Question 4: In FedRAMP supply chain risk management, what does SCRM stand for?
- Supply Chain Risk Management (Correct answer)
- Security Control Remediation Methodology
- System Configuration and Risk Monitoring
- Software Component Reliability Measurement
Correct answer: Supply Chain Risk Management
SCRM stands for Supply Chain Risk Management, which addresses risks from hardware, software, and service providers in the cloud system's supply chain.
Question 5: How must a FedRAMP CSP handle external services or APIs that are integrated into their authorized cloud offering?
- External services must be documented in the SSP and assessed as part of the authorization boundary or accepted as risk (Correct answer)
- External services are automatically inherited from their own FedRAMP authorizations
- External services are excluded from FedRAMP scope if the vendor is a US-based company
- External services only need documentation if they process classified data
Correct answer: External services must be documented in the SSP and assessed as part of the authorization boundary or accepted as risk
All external services within the authorization boundary must be documented in the SSP; if not FedRAMP authorized themselves, they represent risk that must be accepted.
Question 6: What is the FedRAMP requirement regarding 3PAO independence from the CSP they are assessing?
- The 3PAO must have no financial or organizational conflict of interest with the CSP being assessed (Correct answer)
- The 3PAO must be located in a different state than the CSP
- The 3PAO must have assessed at least 5 other cloud providers before assessing the CSP
- The 3PAO must be approved by the specific federal agency sponsoring the authorization
Correct answer: The 3PAO must have no financial or organizational conflict of interest with the CSP being assessed
FedRAMP requires 3PAOs to be fully independent with no financial, organizational, or personal conflicts of interest with the CSP.
What is the primary role of a Third-Party Assessment Organization (3PAO) in the FedRAMP authorization process?