ContinuousMonitoringStrategy&GuideVersion2
0June6,2014ExecutiveSummaryTheOMBmemorandumM-10-15,issuedonApril21,2010,changedfromstaticpointintimesecurityauthorizationprocessestoOngoingAssessmentandAuthorizationthroughoutthesystemdevelopmentlifecycle
ConsistentwiththisnewdirectionfavoredbyOMBandsupportedinNISTguidelines,FedRAMPdevelopedanongoingassessmentandauthorizationprogramforthepurposeofmaintainingtheauthorizationofCloudServiceProviders(CSP)
2010年4月21日,美国政府管理预算局(OMB)发布了M-10-15备忘录,将时间安全授权过程中的静态点改为贯穿系统开发生命周期的持续评估和授权
除了OMB,NIST指导方针也支持了这个新动向,FedRAMP开发了一套持续评估和授权程序用以维持云服务商(CSP)的授权
AfterasystemreceivesaFedRAMPauthorization,itisprobablethatthesecuritypostureofthesystemcouldchangeovertimeduetochangesinthehardwareorsoftwareonthecloudserviceoffering,oralsoduetothediscoveryandprovocationofnewexploit