diff --git a/FRMR.documentation.json b/FRMR.documentation.json index 734361f..cf9fbb8 100644 --- a/FRMR.documentation.json +++ b/FRMR.documentation.json @@ -2,8 +2,8 @@ "info": { "title": "FedRAMP Machine-Readable Documentation", "description": "This datafile contains FedRAMP documentation for cloud service providers seeking FedRAMP Authorization. This includes definitions, requirements, recommendations, and key security indicators.", - "version": "0.9.41-beta", - "last_updated": "2026-03-03" + "version": "0.9.42-beta", + "last_updated": "2026-03-17" }, "FRD": { "info": { @@ -1713,21 +1713,25 @@ "name": "Senior Security Reviewer", "varies_by_level": { "low": { - "statement": "Agencies MAY designate a senior information security official to review Ongoing Authorization Reports and represent the agency at Quarterly Reviews for cloud service offerings included in agency information systems with a Security Category of High.", + "statement": "Agencies MAY designate a senior information security official to review Ongoing Authorization Reports and represent the agency at Quarterly Reviews for cloud service offerings included in agency information systems with a Security Objective of Low.", "primary_key_word": "MAY" }, "moderate": { - "statement": "Agencies MAY designate a senior information security official to review Ongoing Authorization Reports and represent the agency at Quarterly Reviews for cloud service offerings included in agency information systems with a Security Category of High.", + "statement": "Agencies MAY designate a senior information security official to review Ongoing Authorization Reports and represent the agency at Quarterly Reviews for cloud service offerings included in agency information systems with a Security Objective of Moderate.", "primary_key_word": "MAY" }, "high": { - "statement": "Agencies SHOULD designate a senior information security official to review Ongoing Authorization Reports and represent the agency at Quarterly Reviews for cloud service offerings included in agency information systems with a Security Category of High.", + "statement": "Agencies SHOULD designate a senior information security official to review Ongoing Authorization Reports and represent the agency at Quarterly Reviews for cloud service offerings included in agency information systems with a Security Objective of High.", "primary_key_word": "SHOULD" } }, "terms": ["Agency", "Cloud Service Offering", "Quarterly Review"], "affects": ["Agencies"], "updated": [ + { + "date": "2026-03-17", + "comment": "Changed mention of Security Category to security objective and added Low and Moderate." + }, { "date": "2026-02-04", "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes."