It’s time. A few months after joining up with some old colleagues/friends at Fortreum, LLC, I’m pleased to announce that Fortreum Associates, LLC is open for business! Fortreum Associates is a licensed and registered CPA firm that specializes in information security audits, examinations, and attestations (SOC 1 and SOC 2).
Commercial cloud service providers (CSPs) are responsible for maintaining a similar risk profile to the risks identified within their most recent Security Assessment Report (SAR). CSPs submit continuous monitoring deliverables each month for review by the FedRAMP PMO and their sponsoring agency or the Joint Authorization Board (JAB). These deliverables include a Plan of Action & Milestones (POA&M) and a Deviation Request (DR) list. FedRAMP Vulnerability Scanning Guidance from March 2018 requires that the vulnerabilities listed on these documents use the CVSSv3 calculation, when available, to determine a risk rating.
Effective ConMon Strategies for Vulnerability Management
Discover How to Build and Maintain Effective Cybersecurity Program
Developing a Strategic Plan for US Public Sector Compliance Requirements