Skip to content

Commit

Permalink
Update assessor-page.html
Browse files Browse the repository at this point in the history
content policy updates
  • Loading branch information
shivaalipour authored Mar 28, 2024
1 parent 7a42b7f commit 5930c4a
Showing 1 changed file with 4 additions and 4 deletions.
8 changes: 4 additions & 4 deletions _layouts/assessor-page.html
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ <h2 class="partner-header">Partnering with FedRAMP<sup>®</sup></h2>
<p>As independent third parties, they perform initial and periodic assessments of cloud systems based on federal security requirements. The federal government uses 3PAO assessments as the basis for making informed, risk-based authorization decisions for the use of cloud products and services. During FedRAMP assessments, 3PAOs produce a Readiness Assessment Report (RAR), which is required for the Joint Authorization Board (JAB) Authorization process and optional but highly recommended for the Agency Authorization process, and/or a Security Assessment Plan (SAP) and Security Assessment Report (SAR) that is submitted for authorization to a government Authorizing Official (AO).
</p>

<p>A list of FedRAMP recognized Third Party Assessment Organizations (3PAOs) can be found on the <a href="https://marketplace.fedramp.gov/#!/assessors?sort=assessorName" target="_blank" style="cursor: pointer; text-decoration: underline; color: #c71f25;" rel="noopener">FedRAMP Marketplace</a>.
<p>A list of FedRAMP recognized Third Party Assessment Organizations (3PAOs) can be found on the <a href="https://marketplace.fedramp.gov/assessors" target="_blank" style="cursor: pointer; text-decoration: underline; color: #c71f25;" rel="noopener">FedRAMP Marketplace</a>.
</p>
</div>
</div>
Expand Down Expand Up @@ -73,7 +73,7 @@ <h2 class="text-white center">Resources for Assessors</h2>
<div class="tablet:grid-col-6">
<div class="partners-card padding-4 tablet:margin-right-2">
<h3 class="margin-top-0 margin-bottom-3">3PAO Obligations and Performance Standards</h3>
<p> The <em>3PAO Obligations and Performance Standards</em> provides guidance for 3PAOs on demonstrating the quality, independence, and FedRAMP knowledge required as they perform security assessments on cloud systems. </p>
<p> FedRAMP created a conformity assessment process to recognize third party assessment organizations (3PAOs) through accreditation by the American Association for Laboratory Accreditation (A2LA). This process ensures 3PAOs meet the necessary quality, independence, and FedRAMP knowledge requirements, to perform independent security assessments required by FedRAMP. To maintain recognition, 3PAOs must continue to demonstrate independence, quality, and FedRAMP knowledge as they perform security assessments on cloud systems.</p>
<p class="file-type">[File Info: PDF - 458KB]</p>
<div class="margin-top-4 margin-bottom-2">
<a class="partners-download policy-pdf" href="{{site.baseurl}}/assets/resources/documents/3PAO_Obligations_and_Performance_Guide.pdf" target="_blank">Download</a>
Expand All @@ -85,8 +85,8 @@ <h3 class="margin-top-0 margin-bottom-3">3PAO Obligations and Performance Standa
<div class="tablet:grid-col-6 partners-card-mobile-row ">
<div class="partners-card padding-4 tablet:margin-left-2 mobile:margin-top-2 tablet:margin-top-0">

<h3 class="margin-top-0 margin-bottom-3"> FedRAMP Readiness Assessments: A Guide for 3PAOs </h3>
<p> The <em>FedRAMP Readiness Assessments: A Guide for 3PAOs</em> provides 3PAOs with guidance on how best to utilize the RAR. It provides a shared understanding of the RAR’s intent, process, and best practices.</p>
<h3 class="margin-top-0 margin-bottom-3"> 3PAO Readiness Assessment Report Guide</h3>
<p> FedRAMP created the Readiness Assessment Report Guide to assist 3PAOs and cloud service providers on how to best utilize the FedRAMP Readiness Assessment Report (RAR) templates to confirm the full implementation of the CSO’s technical capabilities, which is required for a FedRAMP Readiness Assessment to be successful. This also helps 3PAOs and CSPs understand the rigor that FedRAMP requires for assessments.</p>
<p class="file-type">[File Info: PDF - 342KB]</p>
<div class="margin-top-4 margin-bottom-2">
<a class="partners-download policy-pdf" href="{{site.baseurl}}/assets/resources/documents/3PAO_Readiness_Assessment_Report_Guide.pdf" target="_blank">Download</a>
Expand Down

0 comments on commit 5930c4a

Please sign in to comment.