Metrics Roadmap Metrics
Metric NumberFacingRelevant StakeholderType of MetricFedRAMP Has Control OverNew MetricHigh Level MetricDescriptionConsiderations
 Collaboration powered by Smartsheet   |   Report Abuse
1
1
External3PAOTime / CostNoYesAssessment - 3PAO Time & CostTotal amount of time and overall cost it takes for a FedRAMP-recognized 3PAO to perform:
1. New Initial Assessment
2. Annual Assessment
3. Readiness Assessments
1. Time & cost will vary depending on the size and scope of the assessment.
2
2
ExternalCX AgencyTime / CostNoYesInitial Authorization - Agency Time & CostTotal amount of time and the cost (resourcing) it takes for an agency to perform a review for a cloud service offering for an initial authorization.1. Tracking the amount of time agencies spend authorizing a product, and what might cause that timeline to increase or decrease, is important for the agency's customer experience - a challenge here is identifying when the clock begins and ends to make sure the metric is captured consistently across agencies.

2. Time & cost will vary depending on the size and scope of the assessment. Cost may be difficult to track for agencies who do not have a fee-for-service model.

3. FedRAMP encourages public feedback on how to best capture this metric accurately.
3
3
ExternalCX AgencyTime / CostNoYesReuse Authorization - Agency Time & CostTotal amount of time and the cost for an agency to perform a review for a cloud service offering for a "reuse" authorization.1. Tracking reuse authorization time & cost against initial authorization time shows the value of using an already authorized product.

2. Time & cost will vary depending on system variables. Cost may be difficult to track for agencies who do not have a fee-for-service model.

3. FedRAMP encourages public feedback on how to best capture this metric accurately.
4
4
ExternalCX AgencyTime / CostNoYesContinuous Monitoring - Agency Time & CostIn cases where a single agency is responsible for all continuous monitoring activities of a CSO, this tracks the total overhead costs and time an agency takes on for their continuous monitoring responsibilities.1. This may vary depending on the level of review each agency does and be difficult to track for agencies who do not have a fee-for-service model.

2. Time & cost will vary depending on system variables. Cost may be difficult to track for agencies who do not have a fee-for-service model.

3. FedRAMP encourages public feedback on how to best capture this metric accurately.
5
5
ExternalCX AgencyTime / CostNoYesCentralized Continuous Monitoring - Agency Time & CostIn cases where FedRAMP has centralized ConMon for a CSO, this tracks the total overhead costs and time an agency takes on for their continuous monitoring responsibilities.1. This may vary depending on the level of review each agency does and be difficult to track for agencies who do not have a fee-for-service model.

2. Time & cost will vary depending on system variables.

3. FedRAMP encourages public feedback on how to best capture this metric accurately.
6
6
ExternalCX AgencyTime / CostNoNoDirect Reuse of FedRAMP Authorized ProductsDirect reuse is when an agency official uses pre-existing FedRAMP authorization artifacts, rather than conducting its own independent assessment of FedRAMP’s baseline security controls for a CSP for use of a cloud product.

This is the total number of authorizations represented by ATO/ATU letters on file with FedRAMP.
7
7
ExternalCX AgencyTime / CostNoNoIndirect Reliance of FedRAMP Authorized ProductsIndirect reliance is when an agency authorizing official uses a cloud product that itself relies on an underlying FedRAMP Authorized product.
8
8
ExternalCX CSPTime / CostNoNoCSP DocumentationTotal amount of time and cost it takes a FedRAMP In Process CSP to document security controls
(SSP & attachments)
1. Time will vary depending on multiple variables including: impact level, deployment model, type of service offering, number of contributors, etc...

2. FedRAMP encourages public feedback on how to best capture this metric accurately.
9
9
ExternalCX CSPSecurityYesYesCSP Package Quality - Gap AreasMost common gap areas FedRAMP identifies in packages each quarter
(ie. encryption, boundary diagram, data flow diagrams, DMARC, etc...)

Identifying these areas will help FedRAMP create Knowledge-Based Articles (KBAs) to focus on areas where guidance may be lacking.
10
10
ExternalCX CSPCostNoNoContinuous Monitoring - Ongoing Product MaintenanceMeasures the cost to a CSP in maintaining an active FedRAMP Authorization in the continuous monitoring phase
(ie. the annual assessment, dev, and security staff costs, monthly ConMon meetings, responding to data calls, et cetera)
11
11
InternalProgram PerformanceSecurityNoYesPackage ResubmissionNumber of times a CSP resubmits a package for FedRAMP review for the initial authorization
12
12
InternalProgram PerformanceTimeYesYesFedRAMP Package Queue timeOverall time between when a full initial package is submitted to FedRAMP and the initial review is complete
13
13
InternalProgram PerformanceTimeYesYesFedRAMP Package Review timeOverall time initial authorization package is in active review phase
14
14
InternalProgram PerformanceSecurityYesNo% of marketplace CSPs covered under Centralized Continuous MonitoringCSPs that are covered under centralized continuous monitoring helping to measure growth of the number of CSPs who transition to centralized continuous monitoring
15
15
InternalProgram PerformanceSecurityYesNo% of marketplace CSPs meeting core security requirementsFedRAMP Authorized CSOs that are meeting core security requirements based on current POA&M and ConMon information excluding CSPs under active CAP remediation or suspended.1. This metric will only measure CSPs covered under centralized continuous monitoring.
16
16
InternalProgram PerformanceSecurityNoNo% of systems meeting current package requirementsFedRAMP will provide a list of package requirements as part of the digital authorization process and this will measure the percentage of systems that meet all the requirements.1. This metric will be implemented in the future state for digital authorization packages.
17
17
InternalProgram PerformanceSecurityNoYes% of systems transitioned to current 800-53 revisionThis will track the % of systems that have transitioned from old 800-53 Revision to new
(currently Rev4--> Rev5)
18
18
InternalProgram PerformanceSecurityNoYesNumber of incidents involving FedRAMP Authorized CSOsNumber of incidents that impacted FedRAMP Authorized CSOs within the year
19
19
InternalProgram PerformanceSecurityNoYesType of incidents involving FedRAMP Authorized CSOsType of incidents that impacted FedRAMP Authorized CSOs within the year
20
20
ExternalProgram PerformanceTimeYesNoAuthorization timeline for FedRAMP program authorizationsTime from SAR delivery to authorization for FedRAMP program authorizations1. This is a metric FedRAMP plans to capture once program authorization path is set up.
21
21
InternalProgram PerformanceTimeYesYesPMO Resubmission DurationDuration between CSP re-submission and FedRAMP final review report submission
22
23
24
25
26
27
28
29
30
31