Skip to content

SCN updates in preparation for wide release

Choose a tag to compare

@pete-gov pete-gov released this 20 Feb 15:31
· 4 commits to main since this release
bedfdc2

This release includes minor modifications resulting from the SCN beta:

Changes in this update are tracked in commit bedfdc2.

Changes to the SCN process include:

  • Removed SCN-TRF-OPT as it improperly implied that opting out of a transformative change might mean the risk of the transformative change did not apply; in most cases there is truly no way to opt out of a transformative change.
  • Added notes clarifying certain requirements.
  • Made minor wording changes to clarify certain requirements.
  • Material change warning: SCN-CSO-HIS (Historical Changes) was modified to require 12 months of historical Significant Change Notifications to be retained, regardless of annual assessment. This will help FedRAMP and authorizing officials gauge the effectiveness of a provider's Significant Change Notification program.

Changes in general include:

  • Fixed main BIR page to show Collaborative Continuous Monitoring as being in Open Beta
  • Updated main BIR page to clarify that requirements inside of optional BIRs only apply to providers that adopt the BIR.