Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

yru-weighed
Copy link

Continuous Reporting
The FedRAMP Continuous Reporting Standard establishes requirements for continuous reporting that cloud service providers MUST follow to maintain FedRAMP authorization.

At least the following Key Security Metrics MUST be included in continuous monitoring reports:

Unmitigated Vulnerabilities - A list of unmitigated vulnerabilities or vulnerability groupings, broken down by risk rating, including at least the following information:

Total number of unmitigated items
Common Vulnerabilities and Exposures (CVE) ID, other unique ID if CVE is unavailable, or N/A Provider’s unique tracking identifier for this occurrence Component or Services impacted
Original FedRAMP remediation window end date
Known Exploited Vulnerability status
Remediation and/or mitigation plans, including dates Added details on the FedRAMP Authorization Act and continuous monitoring reporting process for cloud service providers.

Continuous Reporting
The FedRAMP Continuous Reporting Standard establishes requirements for continuous reporting that cloud service providers MUST follow to maintain FedRAMP authorization.

At least the following Key Security Metrics MUST be included in continuous monitoring reports:

Unmitigated Vulnerabilities - A list of unmitigated vulnerabilities or vulnerability groupings, broken down by risk rating, including at least the following information:

Total number of unmitigated items
Common Vulnerabilities and Exposures (CVE) ID, other unique ID if CVE is unavailable, or N/A
Provider’s unique tracking identifier for this occurrence
Component or Services impacted
Original FedRAMP remediation window end date
Known Exploited Vulnerability status
Remediation and/or mitigation plans, including dates
Added details on the FedRAMP Authorization Act and continuous monitoring reporting process for cloud service providers.
@yru-weighed yru-weighed requested a review from a team as a code owner October 23, 2025 06:55
@yru-weighed yru-weighed requested a review from babakks October 23, 2025 06:55
@cliAutomation cliAutomation added the external pull request originating outside of the CLI core team label Oct 23, 2025
@cliAutomation
Copy link
Collaborator

Hi! Thanks for the pull request. Please ensure that this change is linked to an issue by mentioning an issue number in the description of the pull request. If this pull request would close the issue, please put the word 'Fixes' before the issue number somewhere in the pull request body. If this is a tiny change like fixing a typo, feel free to ignore this message.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

external pull request originating outside of the CLI core team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants