FedRAMP Risk Management Framework & Assessment 5 — Questions and Answers
Question 1: A CSP implements a compensating control because the baseline control is technically infeasible. What documentation is required?
- Only verbal approval from the 3PAO lead assessor
- A formal deviation request or alternative implementation documented in the SSP with justification (Correct answer)
- A waiver signed by the FedRAMP PMO Director
- No documentation is needed if the compensating control is NIST-approved
Correct answer: A formal deviation request or alternative implementation documented in the SSP with justification
Compensating controls and deviations must be formally documented in the SSP with a clear justification, showing how the alternative provides equivalent protection.
Question 2: Which of the following best describes the role of NIST SP 800-30 in FedRAMP risk assessments?
- It defines the minimum security requirements for federal information systems
- It provides guidance for conducting risk assessments, including threat identification and likelihood determination (Correct answer)
- It establishes requirements for continuous monitoring programs
- It defines the authorization boundary for cloud systems
Correct answer: It provides guidance for conducting risk assessments, including threat identification and likelihood determination
NIST SP 800-30, 'Guide for Conducting Risk Assessments,' provides the methodology and process for identifying threats, vulnerabilities, and calculating risk that underpins FedRAMP risk assessments.
Question 3: An agency is using a FedRAMP Moderate authorized IaaS. They deploy a custom application that processes Controlled Unclassified Information (CUI). At what impact level must the custom application be assessed?
- Low, because the IaaS is already Moderate authorized
- Moderate, matching the underlying IaaS authorization level (Correct answer)
- High, because CUI always requires High impact assessment
- No additional assessment is needed since the IaaS is already authorized
Correct answer: Moderate, matching the underlying IaaS authorization level
The agency's application must be assessed at Moderate or higher based on FIPS 199 categorization of the CUI it handles; it can leverage the IaaS Moderate controls but must still be assessed itself.
Question 4: What is the significance of the 'impact level' assignment in FedRAMP relative to selecting a security control baseline?
- It determines the cost of the FedRAMP authorization fee
- It directly determines which FedRAMP control baseline (Low, Moderate, or High) must be implemented (Correct answer)
- It determines how many 3PAO assessors must be present during testing
- It sets the maximum number of users allowed to access the system
Correct answer: It directly determines which FedRAMP control baseline (Low, Moderate, or High) must be implemented
The FIPS 199 impact level (Low, Moderate, or High) maps directly to the corresponding FedRAMP security control baseline that the CSP must implement and the 3PAO must assess.
Question 5: Under FedRAMP continuous monitoring requirements, how frequently must CSPs provide vulnerability scan results to the FedRAMP PMO and authorizing agencies?
- Daily
- Weekly
- Monthly (Correct answer)
- Quarterly
Correct answer: Monthly
FedRAMP requires CSPs to submit vulnerability scan results on a monthly basis as part of their continuous monitoring deliverables.
Question 6: A risk assessment identifies a vulnerability with High impact but Very Low likelihood. Using the standard risk matrix approach, what overall risk rating would this typically receive?
- Critical
- High
- Moderate (Correct answer)
- Low
Correct answer: Moderate
In standard risk matrix methodology, combining High impact with Very Low likelihood typically produces a Moderate overall risk rating, as likelihood significantly reduces the combined risk score.
Question 7: Which FedRAMP document serves as the formal agreement between the CSP and federal agencies that details roles, responsibilities, and service-level commitments?
- System Security Plan (SSP)
- Customer Responsibility Matrix (CRM) (Correct answer)
- Terms of Service (ToS) / Master Service Agreement
- Authorization to Operate (ATO) letter
Correct answer: Customer Responsibility Matrix (CRM)
The Customer Responsibility Matrix (CRM) defines which security controls are managed by the CSP, which are the customer's responsibility, and which are shared between both parties.
A CSP implements a compensating control because the baseline control is technically infeasible.
What documentation is required?