Kayne and Tom talk about the major pillars of Configuration Management. While digging into inventory management, baseline configurations, configuration drift, and risk, they tackle Bell’s Two Hearted American IPA.
Reference documents:
-https://www.fedramp.gov/assets/resources/documents/FedRAMP_Security_Controls_Baseline.xlsx
https://www.gsa.gov/cdnstatic/FedRAMP_Control_Quick_Guide_V12_%281%29.pdf
https://stateramp.org/wp-content/uploads/2021/05/CM_POL_V1.0_20210406.docx
https://learn.microsoft.com/en-us/azure/governance/policy/samples/fedramp-moderate#configuration-management
▬ Contents ▬▬▬▬▬▬▬▬▬▬
0:00 - Intro
1:09 - Beer background
4:36 - What is configuration management under FedRAMP?
5:37 - Why is it important to establish baseline configurations, and how does that contribute to the security of FedRAMP Moderate cloud systems?
6:41 - What is a recommended approach for cloud service providers to maintain an inventory of all hardware and software components?
7:57 - How does the configuration management control domain address vulnerability management for cloud systems?
8:37 - When implementing system changes, how can organizations ensure that they do not inadvertently reduce security or create vulnerabilities?
10:42 - And does that mean that we need to create and maintain change logs with all approved changes to the system, including modifications to hardware, software, and firmware?
11:39 - How do organizations periodically assess the effectiveness of their configuration management processes in maintaining the security of their cloud systems?
The Drafting Compliance series:
To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.