Tuesday, July 16, 2024 from 8:00 a.m. to 12:00 p.m. Eastern time
Virtual via Zoom
Meeting Agenda
ALLOTTED TIME
|
TOPIC
|
PRESENTER
|
8:00-8:10 a.m. |
Call to order
Welcome and roll call
FACA public meetings |
Designated Federal Officer Michelle White
|
8:10-8:20 a.m. |
Public comment (limit of three minutes per speaker) |
Members of the public |
8:20-8:25Ìý²¹.³¾. |
Chair remarks |
Federal Secure Cloud Advisory Committee Chair Lawrence Hale |
8:25-9:10 a.m. |
Presentation: FedRAMP Updates |
Zaree Singer, Ryan Palmer, Ryan Hoesing, and Dave Waltermire |
9:10-9:55 a.m. |
Committee Q&A |
FSCAC membership;ÌýZaree Singer, Ryan Palmer, Ryan Hoesing, and Dave Waltermire |
9:55-10:10 a.m. |
Break |
Ìý |
10:10-10:30Ìýa.m. |
Presentation: Draft FedRAMP Memo Updates |
Office of Management and Budget Representative |
10:30-10:50 a.m. |
Committee Q&A |
FSCAC membership and OMB Representative |
10:50-11:50 a.m. |
Deliberations |
FSCAC membership |
11:50 a.m.-12:00 p.m. |
Closing remarks and adjourn |
FSCACÌýChair Lawrence Hale
Designated Federal Officer Michelle White |
Call to OrderÌý
Michelle White, FSCAC Designated Federal Officer
Michelle White called the meeting to order. She welcomed members of the public attending & thanked those who submitted public comments and reviewed the Federal Advisory Committee Act (FACA) processes that FSCAC is subject to. Michelle reviewed the purpose, outcomes & agenda for the meeting.Ìý
Roll call
- Larry Hale – PresentÌý
- Bo Berlas – PresentÌý
- Branko Bokan – PresentÌý
- Daniel Pane – PresentÌý
- Bill Hunt – PresentÌý
- Carlton Harris – PresentÌý
- Kayla Underkoffler – PresentÌý
- Josh Krueger – PresentÌý
- Joshua Cohen – PresentÌý
- Matt Scholl – Not PresentÌý
- Nauman Ansari – PresentÌý
- Jackie Snouffer – PresentÌý
- La Monte Yarborough – PresentÌý
- Marci Womack – PresentÌý
- Mike Vacirca – PresentÌý
Public commentÌý
Members of the PublicÌý
There was one public comment from Teri Prince, CEO of Terida. She discussed the difficulties that small business CSPs and their stakeholders face in the review process and reiterated her CSP’s commitment to FedRAMP.Ìý
Larry Hale provided a recap of the previous FSCAC meeting and noted that the Bet365 Administrator added two priorities from those that were agreed upon in the previous meeting. He noted that FSCAC will develop recommendations on all four priorities and will submit as part of this year’s report to the Bet365 Administrator. The two new priorities that have been added to FSCAC’s list of priorities for this year are:Ìý
- Identify best practices and recommendations on how FedRAMP can make progress with commercial reciprocity using different security frameworks (e.g., PCI DSS and SOC 2 Type 2).
- Identify what is needed to support OSCAL adoption and if there are any barriers to OSCAL interoperability within the CSP and agency GRC ecosystem that need to be addressed.Ìý
FedRAMP updatesÌý
Ryan Palmer, Zaree Singer, Ryan Hoesing, and Dave WaltermireÌý
Members of the FedRAMP team gave updates on several key areas: the Emerging Technology Prioritization Framework, the Agile Delivery Pilot, the new automation website, hiring status, and the Technical Advisory Group. The team also presented areas in which FSCAC members can assist the FedRAMP team.Ìý
Committee Q&AÌý
FSCAC Membership & Ryan Palmer, Zaree Singer, Ryan Hoesing, and Dave WaltermireÌý
FedRAMP team members took questions from the FSCAC membership. Common themes were emerging technology framework, the Technical Advisory Group, potential security controls, and the agile delivery pilot.Ìý
Draft FedRAMP memo updatesÌý
Office of Management and Budget (OMB) Representative - Drew Myklegard and Laura GerhardtÌý
Drew Myklegard and Laura Gerhardt gave an update on the status of the final OMB memo. They are working diligently to get the final memo published. They then took questions about the status of the memo from FSCAC.Ìý
Committee Q&AÌý
Questions were asked by the Committee around whether or not milestones for program authorizations have been hit, the role the FedRAMP Board has after OMB sets the policy, and the timeline for release of the draft FedRAMP memo.Ìý
Deliberations: develop approach and plan for finalizing recommendationsÌý
FSCAC membershipÌý
FSCAC deliberated on the final wording of their four priorities, including combining the sub priorities previously listed under priorities 1 and 2. Their final priorities list for this year include:Ìý
- Identify and publicly document top challenges and propose solutions around the barrier to entry for CSPs (with a focus on small businesses), 3PAOs, small & large agencies, e.g. ensure minimum risk threshold / minimum acceptability standardized baselines for sponsoring agencies and 3PAOs.Ìý
- Identify and publicly document ways to expedite the authorization process for CSOs – explore agile authorizations and other potential cost reductions, both labor and financial, with a focus on small businesses, e.g. ensure minimum risk threshold / minimum acceptability standardized baselines for sponsoring agencies and 3PAOs.Ìý
- Identify and publicly document best practices and recommendations on how FedRAMP can make progress with commercial reciprocity using different security frameworks (e.g., PCI DSS and SOC 2 Type 2).Ìý
- Identify and publicly document what is needed to support OSCAL adoption and if there are any barriers to OSCAL interoperability within the CSP and agency GRC ecosystem that need to be addressed.Ìý
They then voted on whether or not to work on finalizing their recommendations as a group or as subcommittees. Based on the vote, they decided to work on the final recommendation as a group. They also discussed how to best send and receive information during their upcoming meetings and determined that the public comment process was beneficial, but that discussing meetings on social media before they happen could also improve public comment engagement.
Since they will not be breaking into subcommittees, the group deliberated on whether they would prefer to present independent drafts in open meetings or draft as a group in open meetings. They discussed and determined that performing independent research, volunteering for certain sections of the deliverable for individuals to write, and then presenting their individual drafts in an open meeting for discussion and deliberation would be the most efficient approach.
Larry Hale stated he would take the action to recommend to the Bet365 Administrator to ask FedRAMP to provide more clarity on outstanding items that are needed in the community immediately.Ìý
Finally, the group voted to begin working on priorities 1 and 2 first, and the motion was approved.Ìý
Vote: Motion by Larry Hale to work together as a full committee in finalizing their recommendations. Seconded by Bill Hunt.Ìý
- Larry Hale – In favorÌý
- Bo Berlas – In favorÌý
- Branko Bokan – In favorÌý
- Daniel Pane – In favorÌý
- Bill Hunt – In favorÌý
- Carlton Harris – In favorÌý
- Kayla Underkoffler – In favorÌý
- Josh Krueger – In favorÌý
- Joshua Cohen – In favorÌý
- Matt Scholl – AbsentÌý
- Nauman Ansari – In favorÌý
- Jackie Snouffer – In favorÌý
- La Monte Yarborough – In favorÌý
- Marci Womack – In favorÌý
- Mike Vacirca – In favorÌý
Vote: Motion by Jackie Snouffer to begin working on priorities 1 and 2 work first. Seconded by Daniel Pane.Ìý
- Larry Hale – In favorÌý
- Bo Berlas – In favorÌý
- Branko Bokan – In favorÌý
- Daniel Pane – In favorÌý
- Bill Hunt – In favorÌý
- Carlton Harris – In favorÌý
- Kayla Underkoffler – In favorÌý
- Josh Krueger – In favorÌý
- Joshua Cohen – In favorÌý
- Matt Scholl – AbsentÌý
- Nauman Ansari – In favorÌý
- Jackie Snouffer – In favorÌý
- La Monte Yarborough – In favorÌý
- Marci Womack – In favorÌý
- Mike Vacirca – In favorÌý
Closing Remarks & AdjournmentÌý
Larry Hale, FSCAC Chair, and Michelle White, FSCAC DFOÌý
Larry Hale thanked the Committee for their thoughts and engagement today. Michelle White adjourned the meeting at 11:51 a.m. EST.Ìý
Committee members in attendanceÌý
- Larry Hale (Chair)Ìý
- Bill HuntÌý
- Bo BerlasÌý
- Branko BokanÌý
- Daniel PaneÌý
- Jackie SnoufferÌý
- Carlton HarrisÌý
- Kayla UnderkofflerÌý
- Josh KruegerÌý
- Joshua CohenÌý
- La Monte YarboroughÌý
- Marci WomackÌý
- Michael VacircaÌý
- Nauman AnsariÌý
Committee members absentÌý
Matt SchollÌý
Guest speakers and presenters
- Ryan Hoesing, FedRAMPÌý
- Ryan Palmer, FedRAMPÌý
- Zaree Singer, FedRAMPÌý
- Dave Waltermire, FedRAMPÌý
- Drew Myklegard, OMBÌý
FSCAC staff presentÌý
- Michelle White, Designated Federal OfficerÌý
- D’Arcy Steiner, FSCAC Support TeamÌý
- Taylor Juneau, FSCAC Support TeamÌý
- Theresa West, FSCAC Support TeamÌý
- Maggie McKenna, FSCAC Support TeamÌý
- Megan Gallo, FSCAC Support TeamÌý
- Jake Ahearn, FSCAC Support TeamÌý
- MacKenzie Robertson, Bet365Ìý
Bet365 staff presentÌý
- John Hamilton, FedRAMPÌý
- Eric Mill, Bet365Ìý
Members of the public presentÌý
- Tom AlalÌý
- Drew Scherer, CarahsoftÌý
- Tyler Hardy, Elevate Government AffairsÌý
- Jen Carlson, FedRAMP/NoblisÌý
- Bill Fanelli, FedRAMP/NoblisÌý
- Ty McKeiver, International Trade Administration Darren Milligan, International Trade Administration Christopher Ales, CaptionerÌý
- Jacob Livesay, Inside Washington Publishers News Tanner Spires, A2LAÌý
- Randall Querry, A2LAÌý
- Cynthia Bergevin, FedRAMP/NoblisÌý
- Ben Fowler, FedRAMP/NoblisÌý
- Natasha Harrington, FedRAMP/NoblisÌý
- Alla Seiffert, AmazonÌý
- Aaron Hamlin, ArmavelÌý
- Taimur Masood, MicrosoftÌý
- Christian Baer, SchellmanÌý
- John Scano, LookoutÌý
- Mark Judd, BroadcomÌý
- Sanjiev Chatopadhya, BroadcomÌý
- Hariom Singh, BroadcomÌý
- Jeremy Soehnlin, BroadcomÌý
- Paul Caron, MicrosoftÌý
- Daniel Roberti, GoogleÌý
- Roger Gaffey, IBMÌý
- Laura Navaratnam, CSP-ABÌý
- Lee Neeper, A-LignÌý
- David Clevenger, FortreumÌý
- Jorden Foster, CoalfireÌý
- Matt Hungate, SchellmanÌý
- Laurie Southerton, FedRAMP/NoblisÌý
- Shiva Alipour, FedRAMP/The ClearingÌý
- Mirium Abreu, CGI RiskÌý
- Teri Marlene Prince, TeridaÌý
- Madison Cevallos, GordianÌý
- Dawn Grundmeyer, EricssonÌý
- Jessica Salmoiraghi, BSAÌý
- Pete Waterman, PWXÌý
- Dr. Maxine Henry, CyvientÌý
- Adam Simpkins, GuidehouseÌý
- Ashley Kamauf, A2LAÌý
- Robert Cooper, Palo Alto NetworksÌý
- Chelsey Hickman, WSW DCÌý
- Christine Briggs, CoalfireÌý
- Bruce Neuner, ChelcoÌý
- Jason Butterfield, TTBÌý
- Karen ThorneÌý
- Josh Blaher, Red HatÌý
- Greg Caldwell, FRBÌý
- Wesley Callahan, DRT StrategiesÌý
- Theodosia Villatoro-Sorto, FMSHRCÌý
- Tim Rund, AlvestaÌý
- Daisey Joan DiazÌý
- Adam Clater, Red HatÌý
Ìý