Which of the following BEST describes a government –wide standard for security Assessment and Authorization (A&A), and continuous monitoring for cloud products and services, which is mandatory for federal agencies and Cloud Services Providers (CSP)?
Answer:B
B. National Institute of Standards and technology (NIST)
Government team conducted an ongoing monitering, security Assessment of cloud based on the continuous process described in NIST. It is a part of ensuring that we meet FedRAMP requirement. In FedRAMP cloud security posture is monitored according to the assessment and authorization process. Monitoring security controls is a part of risc management framework for information security to maintain a security authorization.
Get Answers For Free
Most questions answered within 1 hours.