Low New document us

FedRAMP adds RFC-0031 Updated Incident Communications Procedures

Original title: Added RFC-0031 Updated Incident Communications Procedures

FedRAMP has added RFC-0031 Updated Incident Communications Procedures to its compliance framework. This new procedure updates how cloud service providers must communicate security incidents to government agencies. Organizations operating under FedRAMP authorization need to review and implement the updated incident communications procedures as defined in RFC-0031.

What changed

  • RFC-0031 Updated Incident Communications Procedures has been added to FedRAMP requirements. This document establishes or revises the procedures that cloud service providers must follow when communicating security incidents to federal agencies and stakeholders.

Who is affected

Cloud service providers (CSPs) authorized under FedRAMP and federal agencies that oversee or consume FedRAMP-authorized cloud services in the United States.

Language
EN

Frameworks

FedRAMP

Open the original source