Yes, Cloud service providers, in the continuous monitoring (ConMon) phase, are required to utilize automated scanning tools to perform service configuration scans monthly and provide the scan results to the FedRAMP documentation repository as part of the monthly ConMon deliverable. 3PAOs will ensure that service configuration scans are performed during annual assessments and provide those scans as part of the SAR.
Comments
0 comments
Please sign in to leave a comment.