False Positive Vulnerability
FRD-FPVA detected vulnerability that is not actually present in an exploitable state in the information resource
Also:false positive vulnerabilityfalse positive vulnerabilities
Federal Customer Data
FRD-FCDAll electronic information, content, and materials that an agency or its authorized users upload, store, or otherwise supply to a cloud service for processing or storage. This does NOT include account information, service metadata, analytics, telemetry, or other similar metadata generated by the cloud service provider.
In the context of FedRAMP Certification, "federal customer data" ONLY ever refers to data owned by federal agency customers. Agreements and contracts with specific agencies may require providers to protect additional data or even transfer ownership of telemetry or usage data to the agency; always consult a lawyer that is familiar with company agreements and contracts when determining the scope of federal customer data.
Also:federal customer data
FedRAMP Certification Report
FRD-FCRA report that is produced by FedRAMP documenting the results of a FedRAMP Certification assessment. This report is typically produced after the initial FedRAMP Certification assessment on the Program Certification Path and updated as necessary during ongoing FedRAMP Certification, but may be produced at any time by FedRAMP as part of ongoing FedRAMP Certification activities for any cloud service offering (such as corrective action). Cloud service offerings must include these reports in their FedRAMP Certification Package.
Also:FedRAMP Certification ReportFedRAMP certification reportcertification report
FedRAMP Certified
FRD-FCTThe status of a cloud service offering that has received FedRAMP Certification and meets the legal requirement to be FedRAMP authorized.
FedRAMP uses "FedRAMP Certified" as the current program term for cloud service offerings that satisfy the statutory concept of FedRAMP authorization.
Also:FedRAMP CertifiedFedRAMP certifiedcertifiedFedRAMP authorizedFedRAMP Authorizedauthorized
FedRAMP Independent Assessment
FRD-FINAn independent verification and validation assessment, performed by a FedRAMP Recognized independent assessment service or FedRAMP following FedRAMP rules. These assessments are typically first performed to obtain an initial FedRAMP Certification then repeated on an annual basis to maintain FedRAMP Certification.
Also:FedRAMP independent assessmentFedRAMP independent assessments
FedRAMP Practices
FRD-FPRThe security measures, safeguards, precautions, procedures, activities, policies, capabilities, mechanisms, etc. that are expected to be in place by FedRAMP to demonstrate that information resources are properly protected, expressed in FedRAMP 20x Key Security Indicators or FedRAMP Rev5 Controls and supplemented by FedRAMP rules.
Also:FedRAMP PracticeFedRAMP Practices
FedRAMP Recognized
FRD-FRAThe status of independent assessment services that are recognized by FedRAMP to perform assessment activities on behalf of FedRAMP for cloud service offerings seeking to obtain or maintain FedRAMP Certification.
Also:FedRAMP RecognizedFedRAMP Recognition
FedRAMP Reportable Incident
FRD-FRIAn incident that affects the confidentiality or integrity of federal customer data or is likely to affect the confidentiality or integrity of federal customer data.
Also:FedRAMP Reportable IncidentFedRAMP Reportable Incidents
FedRAMP Security Inbox
FRD-FSIAn email address that follows the FedRAMP Security Inbox rules.
Also:security inboxsecurity inboxesFSI
Final Incident Report (FIR)
FRD-FIRA final report after recovery from an incident that is supplied by FedRAMP Certified cloud service providers to FedRAMP and agency customers, following FedRAMP Incident Evaluation and Response rules.
Also:final incident reportfinal incident reportsFIRFIRs
Fully Mitigated Vulnerability
FRD-FMVA vulnerability where the likelihood of exploitation or Potential Agency Impact N-rating has been reduced from the original evaluation until either are negligible, but the vulnerability is still detected.
Also:fully mitigated vulnerabilityfully mitigated vulnerabilitiesfully mitigate vulnerabilities