A CSP uses a subcontractor to provide physical data center services. Under FedRAMP, how must this relationship be handled?
-
A
The subcontractor is excluded from FedRAMP scope since they are not the primary CSP
-
B
The subcontractor's services must be included in the CSP's authorization boundary or separately authorized
-
C
The CSP must obtain a separate ATO for the subcontractor on their behalf
-
D
The agency must directly contract with the subcontractor for security purposes