Your Roadmap to Risk Reduction!

The Continuum GRC ITAM SaaS platform has hundreds of plugin modules available, such as:

Audit and compliance modules for StateRAMP

StateRAMP

StateRAMP was developed with procurement and IT officials in mind – to bridge the gap between the two offices and provide a framework of cybersecurity standards for government contractors. All too often, procurement officials are challenged with procuring the best cloud services and software for the lowest price, without the tools or resources to verify cybersecurity compliance.

While state and local governments have begun to take steps to secure their own databases, not much has been done to validate the oversight and protection of third-party cloud service providers with whom they do business.

Modules include:

  • System Security Plan (SSP) High-Moderate-Low
  • System Security Plan (SSP)
  • Security Assessment Report (SAR)
  • Security Assessment Plan (SAP)
  • Plan of Action and Milestones (POA&M)
  • Customer Responsibility Matrix
  • Electronic Authentication (E-Authentication) Plan
  • Privacy Impact Assessment (PIA)
  • Rules of Behavior (RoB)
  • Information System Contingency Plan (ISCP)
  • CIS for SSP Low, Moderate, or High Baselines
  • Integrated Inventory Workbook
  • Information System Security Policies and Procedures
  • Configuration Management (CM) Plan
  • Control Implementation Summary (CIS)
  • CIS Worksheet
  • IT Contingency Plan (CP)
  • Incident Response Plan (IRP)
  • Rules of Behavior (ROB)
  • AC Access Control
  • AT Awareness and Training
  • AU Audit and Accountability
  • CA Certification, Accreditation, and Security Assessment
  • CM Configuration Management
  • CP Contingency Planning
  • IA Identification and Authentication
  • IR Incident Response
  • MA Maintenance
  • MP Media Protection
  • PE Physical and Environmental Protection
  • PL Planning
  • PS Personnel Security
  • RA Risk Assessment
  • SA System and Services Acquisition
  • SC System and Communications Protection
  • SI System and Information Integrity
  • PM Project Management

    ConMon

    • Continuous Monitoring Activities & Deliverables: Continuous
    • Continuous Monitoring Activities & Deliverables: Weekly
    • Continuous Monitoring Activities & Deliverables: 10 days
    • Continuous Monitoring Activities & Deliverables: Monthly
    • Continuous Monitoring Activities & Deliverables: 60 days
    • Continuous Monitoring Activities & Deliverables: Quarterly (90 days)
    • Continuous Monitoring Activities & Deliverables: Annual
    • Continuous Monitoring Activities & Deliverables: Every 2 years
    • Continuous Monitoring Activities & Deliverables: Every 3 years
    • Continuous Monitoring Activities & Deliverables: Every 5 years
    • StateRAMP Significant Change Request Form
    • StateRAMP Significant Change Request Form: Attachment A

    Policies and Procedures

    • AC – Access Control Policy
    • AC – Access Control Procedure
    • AT – Awareness & Training Policy
    • AT – Awareness & Training Procedure
    • AU – Audit & Accountability Policy
    • AU – Audit & Accountability Procedure
    • CA – Security Assessment and Authorization Policy
    • CA – Security Assessment and Authorization Procedure
    • CM – Configuration Management Policy
    • CM – Configuration Management Procedure
    • CP – Contingency Planning Policy
    • CP – Contingency Planning Procedure
    • IA – Identification & Authentication Policy
    • IA – Identification & Authentication Procedure
    • IR – Incident Response Policy
    • IR – Incident Response Procedure
    • MA – Maintenance Policy
    • MA – Maintenance Procedure
    • MP – Media Protection Policy
    • MP – Media Protection Procedure
    • PE – Physical & Environmental Policy
    • PE – Physical & Environmental Procedure
    • PL – Planning Policy
    • PL – Planning Procedure
    • PS – Personnel Policy
    • PS – Personnel Procedure
    • RA – Risk Assessment Policy
    • RA – Risk Assessment Procedure
    • SA – System & Services Acquisition Policy
    • SA – System & Services Acquisition Procedure
    • SC – System & Communications Protection Policy
    • SC – System & Communications Protection Procedure
    • SI – System & Information Integrity Policy
    • SI – System & Information Integrity Procedure

    Key Components of StateRAMP Assessment

    This form of  cybersecurity evaluation was designed to ensure that cloud service providers that work with state and local governments meet specific standards when dealing with the security of sensitive data. StateRAMP is modeled after FedRAMP,  the cloud security standards required by the federal government.

    A third-party assessment begins with reviewing the key assets of the organization and prioritizing their value to the business. These range from security gap analysis, data collection, general cloud security, employee training, and more.

    Changes are recommended to meet the security compliance standards and continuous  monitoring is established to maintain them. Thorough documentation is also required.

    StateRAMP Assessment Process

    Some initial research is first required to understand the StateRAMP requirements. Finding a third-party assessor like Continuum GRC can smooth the process,  There’s a readiness assessment which is optional, but it will better help identify security gaps for compliance that need to be addressed.

    There are various report levels that need to be addressed detailing specific security controls and procedures, plans of actions, secure cloud services, and the like. Extensive documentation is also required, followed by an executive summary for review by the government. An experienced third-party assessor can expertly navigate your organization through this complex path to achieve this important certification.

    Why Choose US?

    Continuum GRC has years of experience working through the evolving requirements for high-level certifications. We know and understand the small details that can throw off the process and slow it down. We get ahead of those things to keep it all moving forward. 

    Any kind of certification or compliance program that touches on the government necessarily demands exceptional thoroughness and care. We have the expertise to assess where you are, make sensible recommendations, help you implement them, then assist in the required monitoring and needed documentation. Going it alone is costly, time-consuming, and eats up resources. Let us handle it.

    FAQ

    Select the right authorization path for your organization. Choose an authorized third-party auditor like Continuum GRC to oversee the assessment. Gather documentation – policies, plans, and procedures related to information security. Let your third-party assessor conduct the assessment for compliance against StateRAMP requirements. Submit the package for certification, and maintain compliance with regular assessments.

    The StateRAMP compliance process takes about three to six months. It includes completing the application and all required documentation, undergoing a security assessment and remediating any issues that have been reported.  Some state and local organizations who need moderate or high authorization can do  a fast-track process of one to two months.

    As experts in all kinds of certifications, Continuum GRC helps organizations and service providers move through what can be a complicated process. We know the documentation required, how to run an efficient assessment and implement needed fixes. We also understand how to institute the monitoring processes to ensure that you remain in compliance.

    A third-party assessment organization is one that has been authorized to guide an organization – whether public or private – through the needed tests and reviews to achieve certifications of all kinds. Continuum GRC has a deep understanding of the ins and outs of various high-level security checks.

    These are both cybersecurity frameworks for handling sensitive information. StateRAMP are guidelines for use in local and state governments; FedRAMP is for use at the federal level. FedRAMP compliance is mandatory by the General Services Administration, while StateRAMP criteria is voluntary, managed by individual states.

    What are you waiting for?

    You are just a conversation away from putting the power of Continuum GRC to work for you. 

    Contact us using the form below or calling us at 1-888-896-6207 for immediate assistance.

    Amazing Benefits