An organization storing sensitive data in AWS wants to achieve FedRAMP authorization. Which step must come FIRST in the formal authorization process?
-
A
Obtain a Provisional Authorization to Operate (P-ATO) from the JAB
-
B
Complete a System Security Plan (SSP)
-
C
Conduct penetration testing
-
D
Hire a Third Party Assessment Organization (3PAO)