FedRAMP adds RFC-0031 Updated Incident Communications Procedures
Original title: Added RFC-0031 Updated Incident Communications Procedures
FedRAMP has added RFC-0031 Updated Incident Communications Procedures to its compliance framework. This new procedure updates how cloud service providers must communicate security incidents to government agencies. Organizations operating under FedRAMP authorization need to review and implement the updated incident communications procedures as defined in RFC-0031.
What changed
- RFC-0031 Updated Incident Communications Procedures has been added to FedRAMP requirements. This document establishes or revises the procedures that cloud service providers must follow when communicating security incidents to federal agencies and stakeholders.
Who is affected
Cloud service providers (CSPs) authorized under FedRAMP and federal agencies that oversee or consume FedRAMP-authorized cloud services in the United States.
- Language
- EN