|

CSP-AB FedRAMP Day Recap


Part 1: 20x – What Actually Changes

Last week I participated in the CSP-AB Summit and I spent a lot of FedRAMP Day listening for what is actually changing with 20x versus what we’re simply doing differently.

My biggest takeaway: the security fundamentals aren’t changing nearly as much as how we prove them.

For years, we’ve spent a lot of assessment time documenting security through SSP narratives, control descriptions, screenshots and point-in-time evidence. 20x shifts much more of the focus to whether you can demonstrate that the security outcome is actually being achieved – and keep demonstrating it.

That also changes the role of the assessor.

One point the PMO made very clearly is that the 3PAO (now IAS) isn’t there to decide whether a CSP is “secure enough.” The agency owns that risk decision.

Our job is to validate that what the CSP says is true and complete, test the evidence, evaluate whether implementations are effective, and identify concerns. The agency then decides whether that security posture meets its needs.

I also appreciated NIST’s reminder that 800-53 was never intended to be a checklist. There isn’t one right implementation for every security outcome, and there isn’t going to be a clean formula where a specific set of KSIs automatically equals a specific 800-53 control.

After doing this work for a long time, I think that’s a healthy shift.

Less time proving that the documentation says the right thing. More time proving that the security actually works.

That’s the part of 20x I’m most interested in.