<?xml version="1.0" encoding="UTF-8"?><PerformancePlanOrReport xmlns="http://www.stratml.net/PerformancePlanOrReport" Type="Strategic_Plan"><id/><Name>FedRAMP Forward:  2 Year Priorities</Name><Description>FedRAMP Forward prioritizes three key areas of focus. First, increased stakeholder engagement is needed to more fully realize the benefits of FedRAMP across the government. Second, improving efficiencies will allow the FedRAMP process to happen faster and with fewer hurdles. And third, continuing to adapt is critical to staying aligned with the evolving cybersecurity landscape. This plan sets out the objectives and initiatives FedRAMP will pursue over the next two years to address these key issues.</Description><OtherInformation/><StrategicPlanCore><Organization><Name>FedRAMP Program Management Office</Name><Acronym>FRPMO</Acronym><Identifier>_b76fb5f4-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><Description/><Stakeholder><Name/><Description/></Stakeholder></Organization><Vision><Description/><Identifier>_b76fb842-bbaf-11e4-9f9c-c6ad57876c4e</Identifier></Vision><Mission><Description/><Identifier>_b76fb91e-bbaf-11e4-9f9c-c6ad57876c4e</Identifier></Mission><Value><Name/><Description/></Value><Goal><Name>ENGAGEMENT</Name><Description>INCREASE STAKEHOLDER ENGAGEMENT </Description><Identifier>_b76fb9dc-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>FedRAMP and its application to cloud environments is complex and involves a broad array of stakeholders: Federal agencies, 3PAOs, and CSPs. One of the keys to success through FedRAMP is ensuring that stakeholders fully understand the requirements and are actively engaged through the process, from initiation, to authorization, and continuous monitoring.  There are more than 50 CSPs actively engaged in the FedRAMP process, 31 accredited 3PAOs, and nearly every Federal agency is participating in FedRAMP. But these numbers don’t reflect the true marketplace of cloud systems in the Federal government. In order to reach the full breadth of cloud providers working with the Federal government as well as encourage new and innovative services to be available for use, stakeholder engagement with FedRAMP needs to increase. </OtherInformation>
            <Objective>
                <Name>IMPLEMENTATION</Name>
                <Description>INCREASE NUMBER OF AGENCIES IMPLEMENTING FEDRAMP </Description>
                <Identifier>_b76fba86-bbaf-11e4-9f9c-c6ad57876c4e</Identifier>
                <SequenceIndicator>1.1</SequenceIndicator>
                <Stakeholder>
                    <Name/>
                    <Description/>
                </Stakeholder>
                <OtherInformation>In many departments and agencies, FedRAMP implementation is limited to specific programs and the cloud services they are using, rather than being done in an enterprise-wide manner across departments and agencies. FedRAMP implementation will be expanded by:</OtherInformation>
                <PerformanceIndicator ValueChainStage="Input_Processing"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension/>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Baseline FedRAMP use across Federal government with various data points including PortfolioStat and FISMA reporting.
</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Input_Processing"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension/>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Provide practical implementation guidance for agency ATOs for initiating assessments and authorizations, re-use of ATOs, and implementing solutions within an ATO cloud service.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Input_Processing"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Data Normalization</MeasurementDimension>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Normalize agency reported data and enhance guidance on agency reporting of FedRAMP and cloud statistics through PortfolioStat.
</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Success Stories</MeasurementDimension>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Document agency success stories for FedRAMP, establishing a best practice reference guide.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Procurement Options</MeasurementDimension>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Identify procurement options for agencies to obtain FedRAMP implementation support</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Report</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish report documenting current status of FedRAMP metrics and statistics</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description/>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
            </Objective><Objective><Name>Metrics</Name><Description>Establish accurate FedRAMP metrics.</Description><Identifier>_b76fbb3a-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>1.1.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>The FedRAMP PMO will work to better analyze the true breadth of use of FedRAMP across the government -- not just through PortfolioStat analysis -- but through the identification of usage across small and micro agencies, congressional and judicial branch entities, and state and local governments.</OtherInformation></Objective><Objective><Name>Guidance</Name><Description>Create practical implementation guidance. </Description><Identifier>_b76fbbe4-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>1.1.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Guidance will address all use cases of implementations -- including beginning an assessment, re-using an existing assessment, implementing agency responsibilities, transitioning legacy applications in to a cloud infrastructure, and more.</OtherInformation></Objective><Objective><Name>Support</Name><Description>[Provide] additional support for FedRAMP.</Description><Identifier>_b76fbd1a-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>1.1.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Additional support for FedRAMP: It takes people to implement FedRAMP. Many agencies rely on contract resources to assist in their efforts to implement 
FedRAMP. Identification of procurement options for agencies to find the 
specialized expertise needed will be important for agency implementation 
efforts.</OtherInformation></Objective>
            <Objective>
                <Name>COLLABORATION</Name>
                <Description>INCREASE CROSS-AGENCY COLLABORATION</Description>
                <Identifier>_b76fbdf6-bbaf-11e4-9f9c-c6ad57876c4e</Identifier>
                <SequenceIndicator>1.2</SequenceIndicator>
                <Stakeholder>
                    <Name/>
                    <Description/>
                </Stakeholder>
                <OtherInformation>At the heart of FedRAMP is the principle of "do once, use many times." The more the Federal government works together to implement FedRAMP, the more cost savings and efficiencies agencies can realize. The PMO will assist agencies collaborating under FedRAMP by:</OtherInformation>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Multi-Agency Authorization Methodology</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish draft multi-agency authorization methodology following FedRAMP Security Assessment Framework (SAF). </Description>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Working Groups</MeasurementDimension>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Identify and launch working groups for multi-agency authorizations
</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Continuous Monitoring Methodology</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish draft multi-agency continuous monitoring methodology following FedRAMP SAF.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description/>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Continuous Monitoring</MeasurementDimension>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Transition of continuous monitoring from JAB to multi-agency model for JAB P-ATOs that do not reach or achieve government-wide use.
</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description/>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
            </Objective><Objective><Name>Framework</Name><Description>Develop a multi-agency framework.</Description><Identifier>_b76fbed2-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>1.2.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Many CSPs have footprints and established use across multiple agencies. How to effectively and efficiently manage these environments in a collaborative manner needs to be further clarified to establish defined roles and responsibilities to maximize re-use and reduce duplication.</OtherInformation></Objective><Objective><Name>Working Groups</Name><Description>Launch working groups. </Description><Identifier>_b76fc0a8-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>1.2.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>FedRAMP will Formally launch FedRAMP working groups which will give agencies a forum to collaborate as they work through FedRAMP assessments, authorizations and continuous monitoring.</OtherInformation></Objective><Objective><Name>JAB P-ATOs</Name><Description>Ensure JAB P-ATOs cover government-wide use. </Description><Identifier>_b76fc166-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>1.2.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>The JAB's mission is to support CSPs that support the broadest range of government-wide use. The working groups and multi-agency framework will allow the JAB to transition systems they have provisionally authorized to agencies for continuous monitoring for those services that do not reach broad government-wide use.</OtherInformation></Objective>
            <Objective>
                <Name>UNDERSTANDING</Name>
                <Description>INCREASE UNDERSTANDING OF FEDRAMP</Description>
                <Identifier>_b76fc21a-bbaf-11e4-9f9c-c6ad57876c4e</Identifier>
                <SequenceIndicator>1.3</SequenceIndicator>
                <Stakeholder>
                    <Name/>
                    <Description/>
                </Stakeholder>
                <OtherInformation>A clear understanding of FedRAMP and all of its requirements is imperative to any implementation efforts by stakeholders. After two and a half years there have been many lessons learned and a better understanding of the nuances of meeting FedRAMP requirements. To make sure that stakeholders not only understand FedRAMP but benefit from the lessons learned, the PMO will:</OtherInformation>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Training Program</MeasurementDimension>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Develop and launch online FedRAMP training program.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>FedRAMP</MeasurementDimension>
                    <UnitOfMeasurement>Relaunch</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Re-launch FedRAMP.gov to improve user experience and usability.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Procurement Guidance</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish agency procurement guidance (in collaboration with OMB / OFPP).</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Training Module</MeasurementDimension>
                    <UnitOfMeasurement>Development</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Develop FedRAMP training module for agency procurement officials.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension/>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Develop targeted FedRAMP training module for agency program managers.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description/>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Documentation</MeasurementDimension>
                    <UnitOfMeasurement>Updating</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Continued updates to reference and guidance documents.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
            </Objective><Objective><Name>Re-Launch</Name><Description>Re-launch FedRAMP.gov.</Description><Identifier>_b76fc2ce-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>1.3.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Information is useless if it cannot be found. The FedRAMP website will be re-launched in a more user friendly format and re-organized so users can more easily and quickly find the information they need.</OtherInformation></Objective><Objective><Name>Training</Name><Description>Launch Formal Training.</Description><Identifier>_b76fc382-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>1.3.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>FedRAMP is a complex framework with many operational processes across a myriad of stakeholders and responsibilities. All stakeholders need to understand their responsibilities under this framework. A formal training program will help stakeholders gain deeper knowledge and understanding of FedRAMP. The training program will launch with a focus on the key FedRAMP requirements for assessments and authorizations, and will grow to include specific modules targeted to defined stakeholder groups like program managers and procurement officials.</OtherInformation></Objective><Objective><Name>Updates</Name><Description>Continue Updates to Reference and Guidance Documents.</Description><Identifier>_b76fc42c-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>1.3.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>As more agencies move to the cloud and more systems are in use across the Federal government, it is important to share lessons learned. FedRAMP initiated this with the Guide to Understanding FedRAMP. This document will be expanded and continually updated to include those lessons learned over time.</OtherInformation></Objective></Goal><Goal><Name>EFFICIENCIES</Name><Description>IMPROVE EFFICIENCIES </Description><Identifier>_b76fc4ea-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>The FedRAMP Security Assessment Framework (SAF) is complex with multiple 
stakeholders and many dependencies. The process can take anywhere from four months to more than a year to complete. Since June 2012, FedRAMP has developed benchmarks to better understand the level of effort it takes to meet the FedRAMP requirements. These benchmarks have identified key areas in which efficiencies could be realized to reduce the overall time and level of effort required by stakeholders.  Improving efficiency will be critical to the success of many CSPs, 3PAOs and agencies in meeting the FedRAMP requirements and will help reduce the time and cost for the security authorization process, and will help open up the Federal market to smaller and more niche service providers giving the Federal government a greater market of IT providers from which to choose. </OtherInformation>
            <Objective>
                <Name>CONSISTENCY &amp; QUALITY</Name>
                <Description>ENHANCE CONSISTENCY AND QUALITY OF 3PAO ASSESSMENTS AND DELIVERABLES.</Description>
                <Identifier>_b76fc59e-bbaf-11e4-9f9c-c6ad57876c4e</Identifier>
                <SequenceIndicator>2.1</SequenceIndicator>
                <Stakeholder>
                    <Name/>
                    <Description/>
                </Stakeholder>
                <OtherInformation>FedRAMP is the only program that accredits independent assessors for Federal 
cybersecurity standards through the 3PAO accreditation program. 3PAOs provide the government with the independent verification and validation of a CSP’s security implementations and identify any associated risks. The government bases its decision to authorize a service provider on a 3PAOs assessment and accompanying report. Through the 3PAO accreditation program, the PMO will:</OtherInformation>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Guidelines</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish guidelines for 3PAOs to address inconsistencies for security assessment activities, artifacts and methodologies.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Training Module</MeasurementDimension>
                    <UnitOfMeasurement>Development</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Develop FedRAMP 3PAO training module in concert with FedRAMP Accreditation Board.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Requirements</MeasurementDimension>
                    <UnitOfMeasurement>Update</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Update 3PAO requirements to ensure consistency for security assessment activities, artifacts and methodologies</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
            </Objective><Objective><Name>Accreditation Requirements</Name><Description>Update 3PAO accreditation requirements.</Description><Identifier>_b76fc666-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>2.1.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>The current 3PAO requirements have broad applicability through ISO 17020 and a FedRAMP knowledge test. The PMO will incorporate 3PAO Guidelines for specific FedRAMP applications to 3PAO policies and processes in to the official 3PAO requirements.</OtherInformation></Objective><Objective><Name>Training</Name><Description>[Conduct] training program for 3PAOs. </Description><Identifier>_b76fc738-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>2.1.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Training programs for 3PAOs will be developed specifically to address the nuances of security assessments in a cloud environment as well as quality control in the delivery of documentation to the government. This training will be mandatory for 3PAO assessors to complete and be a part of FedRAMP assessments. </OtherInformation></Objective>
            <Objective>
                <Name>DATA AND WORKFLOW</Name>
                <Description>ESTABLISH A FLEXIBLE FRAMEWORK FOR DATA AND WORKFLOW MANAGEMENT</Description>
                <Identifier>_b76fc814-bbaf-11e4-9f9c-c6ad57876c4e</Identifier>
                <SequenceIndicator>2.2</SequenceIndicator>
                <Stakeholder>
                    <Name/>
                    <Description/>
                </Stakeholder>
                <OtherInformation>Automation is already a part of a cloud service providers offering through things like internal management of a cloud service, customer self service provisioning, and elasticity of services consumed. There are existing tools that agencies and CSPs use to automate parts of the FedRAMP process, however not all of them meet FedRAMP documentation requirements and there is not a consistent set of requirements for how systems should incorporate automated data feeds from vendors to analyze. In order to realize automation in these areas the PMO will:</OtherInformation>
                <PerformanceIndicator ValueChainStage="Input_Processing"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Tools &amp; Automation</MeasurementDimension>
                    <UnitOfMeasurement>Identification</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Identify existing workflow tools, control automation, and document automation capabilities.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output_Processing"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Industry Day</MeasurementDimension>
                    <UnitOfMeasurement>Conduct</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Conduct Industry Day on tools and processes for automation of CSP documentation and assessment and continuous monitoring evidence.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Requirements</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish draft requirements for automation of FedRAMP documentation.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Automation Requirements</MeasurementDimension>
                    <UnitOfMeasurement>Documentation</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Finalize automation requirements for FedRAMP documentation.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
            </Objective><Objective><Name>Automation</Name><Description>Identify existing automation capabilities.</Description><Identifier>_b76fc8fa-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>2.2.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Since there are already players in this space across not only government but industry, FedRAMP will identify and work with these existing service providers to better understand their tools and the scope of their capabilities.</OtherInformation></Objective><Objective><Name>Requirements</Name><Description>Develop FedRAMP specific automation requirements.</Description><Identifier>_b76fc9fe-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>2.2.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>FedRAMP requires specific formatting and templates in order to maximize re-use. As such, the development of FedRAMP specific automation requirements will help 
stakeholders apply automation in a way that can fully meet FedRAMP. These 
requirements will be created through an initial industry day with identified 
service providers and subsequent public comment periods.</OtherInformation></Objective>
            <Objective>
                <Name>INDUSTRY STANDARDS</Name>
                <Description>RE-USE RE-USE INDUSTRY STANDARDS</Description>
                <Identifier>_b76fcac6-bbaf-11e4-9f9c-c6ad57876c4e</Identifier>
                <SequenceIndicator>2.3</SequenceIndicator>
                <Stakeholder>
                    <Name/>
                    <Description/>
                </Stakeholder>
                <OtherInformation>FedRAMP is not the only cybersecurity compliance standard. There are other examples of cybersecurity standards cloud providers might be required to meet -- ISO, HIPAA, CIJIS, CSA STARS, SOC II -- to name a few. Cloud providers that meet more than one of these compliance standards carry a heavy burden to meet all of these compliance frameworks. Many times CSPs are not able to re-use the evidence for compliance efforts from one framework to another. The goal of all cybersecurity compliance efforts is to demonstrate that an environment is secure enough to protect data according to various standards. In order to help CSPs and 3PAOs realize efficiencies in FedRAMP assessments and authorization through re-use of evidence across various compliance frameworks, the FedRAMP PMO will:
</OtherInformation>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Requirements</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish draft requirements for re-use of external industry compliance evidence for assessment, authorization and continuous monitoring </Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Compliance Framework</MeasurementDimension>
                    <UnitOfMeasurement>Mapping</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Identify and map one external industry compliance framework for re-use of evidence for assessment, authorization and continuous monitoring. </Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension/>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Complete pilot assessment of one CSP re-using evidence from external compliance framework.
</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Compliance Frameworks</MeasurementDimension>
                    <UnitOfMeasurement>Mappings</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish additional mappings of external industry compliance frameworks for evidence re-use.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
            </Objective><Objective><Name>Re-Use Requirements</Name><Description>Publish re-use requirements.</Description><Identifier>_b76fcb98-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>2.3.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Re-use of evidence will require a close attention to scoping and ensuring the evidence being re-used equally applies to two or more industry standards. The requirements must be clear as to what must be met in order to re-use evidence from one framework to another.</OtherInformation></Objective><Objective><Name>Standards Mapping</Name><Description>Map re-use standards to industry requirements.</Description><Identifier>_b76fcc74-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>2.3.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Once the re-use requirements are complete, they will need to be applied to an industry standard for practical application and use. As these mappings are created, they will be piloted with CSPs and authorizing officials to ensure accuracy and develop lessons learned.  These pilots will help formalize industry mappings and guide future efforts.</OtherInformation></Objective></Goal><Goal><Name>ADAPTATION</Name><Description>CONTINUE TO ADAPT </Description><Identifier>_b76fcd8c-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder><Name>NST</Name><Description/></Stakeholder><Stakeholder><Name>DHS</Name><Description/></Stakeholder><OtherInformation>While there are seemingly strict confines around which FedRAMP was built, the key to FedRAMP’s success is the adaptability of FISMA, NIST standards, and DHS guidance. In order for FedRAMP to continue its growth, it is recognized that the cybersecurity landscape evolves constantly -- practically on a minute to minute basis -- and the adaptability must also apply to FedRAMP as it continues to apply FISMA, NIST standards, and DHS guidance. 
As the Federal government matures in its application of cybersecurity standards, there are opportunities for FedRAMP to help coordinate efforts among Federal agencies using CSPs. Adapting to meet the evolving cloud offerings and introduction of new services, the levels of data the government is placing in cloud environments, and placing a higher focus on overall risk management instead of compliance will keep FedRAMP ahead of the curve and ensure all stakeholder needs are being met. </OtherInformation>
            <Objective>
                <Name>MONITORING</Name>
                <Description>EVOLVE CONTINUOUS MONITORING</Description>
                <Identifier>_b76fce90-bbaf-11e4-9f9c-c6ad57876c4e</Identifier>
                <SequenceIndicator>3.1</SequenceIndicator>
                <Stakeholder>
                    <Name/>
                    <Description/>
                </Stakeholder>
                <OtherInformation>Part of meeting the FedRAMP requirements includes adherence to the "FedRAMP Continuous Monitoring Strategy and Guide." This guide has three key areas: periodic reporting, change management, and incident response. Many of the requirements within the "FedRAMP Continuous Monitoring Strategy and Guide" are based on compliance activities. In order to have more effective continuous monitoring, risk management needs to be more fully incorporated. The FedRAMP PMO will evolve the continuous monitoring approach by:</OtherInformation>
                <PerformanceIndicator>
                    <MeasurementDimension/>
                    <UnitOfMeasurement/>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish roadmap for evolution of continuous monitoring to include ongoing authorizations, near real time risk analysis, and greater emphasis on risk management.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Risk Analysis Guidelines</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish guidelines with key indicators for authorizing officials to effectively perform risk analysis and more readily identify and respond to changes in risk posture of systems with existing authorizations.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Guidelines &amp; Requirements</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish guidelines and requirements for automating and correlating continuous monitoring data across agency and JAB authorized systems. </Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Monitoring Data</MeasurementDimension>
                    <UnitOfMeasurement>Automation &amp; Correlation</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Automate and correlate of continuous monitoring data across 2 agency and 2 JAB authorizations.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Reporting Data</MeasurementDimension>
                    <UnitOfMeasurement>Automation &amp; Correlation</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Automate and correlate continuous monitoring and incident reporting data across all JAB and participating agency FedRAMP authorizations.
</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description/>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
            </Objective><Objective><Name>Monitoring Requirements</Name><Description>Updating continuous monitoring requirements.</Description><Identifier>_b76fd002-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>3.1.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Through dialogue with service providers and Federal agencies, and key stakeholders like NIST and DHS, FedRAMP will update the continuous monitoring requirements to have a key focus on risk management through more real time views of CSP environments and establishing key indicators for reviewing CSP risks.</OtherInformation></Objective><Objective><Name>Reporting Requirements</Name><Description>Establish continuous monitoring reporting requirements.</Description><Identifier>_b76fd138-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>3.1.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>In order to effectively monitor agencies use of multiple environments across various CSPs, reporting of continuous monitoring needs to be done consistently. FedRAMP will create and refine reporting requirements so agencies will be able to re-use CSP continuous monitoring deliverables consistently across agencies. </OtherInformation></Objective><Objective><Name>Authorization Correlation</Name><Description>Correlate continuous monitoring activities across authorizations.</Description><Identifier>_b76fd322-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>3.1.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>As CSPs meet the continuous monitoring reporting requirements, correlating the data across all authorizations will give the Federal government a greater ability to 
understand risk as it relates across all applicable environments. FedRAMP will 
enable agencies to have insight to continuous monitoring data on all of the 
systems they use.</OtherInformation></Objective>
            <Objective>
                <Name>BASELINES</Name>
                <Description>ESTABLISH ADDITIONAL BASELINES </Description>
                <Identifier>_b76fd444-bbaf-11e4-9f9c-c6ad57876c4e</Identifier>
                <SequenceIndicator>3.2</SequenceIndicator>
                <Stakeholder>
                    <Name/>
                    <Description/>
                </Stakeholder>
                <OtherInformation>FedRAMP launched with a baseline for low and moderate impact systems, which covers approximately 80% of Federal information systems. Over the last two and a half years, agencies have been rapidly moving to the cloud and showing a strong desire to move more and more mission critical services to the cloud, including some with higher sensitivity levels of data. To ensure that FedRAMP requirements and baselines meet these evolving stakeholder needs, the FedRAMP PMO will:</OtherInformation>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Baseline</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish draft high baseline for public comment.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>High Watermark Baseline</MeasurementDimension>
                    <UnitOfMeasurement>Finalization</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Finalize high watermark baseline.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Input_Processing"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Additional Baselines</MeasurementDimension>
                    <UnitOfMeasurement>Identification</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Identify need for additional agency baseline requirements.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Baseline</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish draft flexible baseline based on identified agency needs.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
            </Objective><Objective><Name>Baseline</Name><Description>Develop a high baseline.</Description><Identifier>_b76fd548-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>3.2.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Almost since inception, all of the FedRAMP stakeholders have asked when a high baseline would be developed. The FedRAMP PMO will work with the JAB to develop a high impact baseline, and will coordinate the vetting process through the CIO Council, ISIMC, and multiple rounds of public comment.</OtherInformation></Objective><Objective><Name>Baseline Needs</Name><Description>Identify additional baseline needs.</Description><Identifier>_b76fd64c-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>3.2.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>FedRAMP will also continue to assess the need for additional baselines and develop those as necessary. Possibilities include systems that meet the requirements for high availability but only need moderate protections for confidentiality and integrity.</OtherInformation></Objective>
            <Objective>
                <Name>CYBER INITIATIVES &amp; POLICY REFORM </Name>
                <Description>ENHANCE INTEGRATION WITH CYBER INITIATIVES AND CONTRIBUTE TO POLICY REFORM </Description>
                <Identifier>_b76fd750-bbaf-11e4-9f9c-c6ad57876c4e</Identifier>
                <SequenceIndicator>3.3</SequenceIndicator>
                <Stakeholder>
                    <Name/>
                    <Description/>
                </Stakeholder>
                <OtherInformation>Technology serves as the intersection for many Government-wide initiatives – and this provides agencies with a challenge to ensure they meet a multitude of requirements when using a single solution. Requirements such as the Trusted Internet Connection (TIC), Homeland Security Protocol Directive-12 (HSPD-12), Internet Protocol version 6 (IPV6), and Continuous Diagnostic and Mitigation (CDM) have critical requirements overlapping with some of the FedRAMP requirements. In order to address this challenge, the FedRAMP PMO will:</OtherInformation>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Framework</MeasurementDimension>
                    <UnitOfMeasurement>Development</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Develop framework for FedRAMP assessment overlay for compliance with relevant IT policies (e.g. TIC, IPv6).</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Assessment Overlay</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish draft initial FedRAMP assessment overlay with 1 to 2 IT policies.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Input_Processing"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Assessments</MeasurementDimension>
                    <UnitOfMeasurement>Conduct</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Conduct concurrent assessments of FedRAMP and additional IT policies.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2015-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Assessment Overlay Framework</MeasurementDimension>
                    <UnitOfMeasurement>Finalization</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Finalize FedRAMP assessment overlay framework. </Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Guidance Methodology</MeasurementDimension>
                    <UnitOfMeasurement>Publication</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Publish formal guidance methodology for assessment overlays IT mandates.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-06-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
                <PerformanceIndicator ValueChainStage="Output"
                    PerformanceIndicatorType="Qualitative">
                    <MeasurementDimension>Assessment Overlays</MeasurementDimension>
                    <UnitOfMeasurement>Development</UnitOfMeasurement>
                    <MeasurementInstance>
                        <TargetResult>
                            <Description>Develop two additional FedRAMP assessment overlays for compliance with additional IT initiatives.</Description>
                            <StartDate>2014-12-17</StartDate>
                            <EndDate>2016-12-17</EndDate>
                        </TargetResult>
                        <ActualResult>
                            <Description>To be reported</Description>
                        </ActualResult>
                    </MeasurementInstance>
                </PerformanceIndicator>
            </Objective><Objective><Name>Assessments</Name><Description>Develop FedRAMP assessment overlays.</Description><Identifier>_b76fd840-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>3.3.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>Agencies, CSPs, and 3PAOs should be able to demonstrate compliance with multiple agency initiatives when undergoing any compliance activity. FedRAMP will create overlays to the FedRAMP Security Assessment Framework that will allow for assessments to demonstrate compliance with FedRAMP but also other initiatives like HSPD-12, IPv6, TIC, CDM, etc.</OtherInformation></Objective><Objective><Name>Engagement</Name><Description>Active engagement with broader cybersecurity community.</Description><Identifier>_b76fd94e-bbaf-11e4-9f9c-c6ad57876c4e</Identifier><SequenceIndicator>3.3.2</SequenceIndicator><Stakeholder><Name>Cybersecurity Community</Name><Description/></Stakeholder><OtherInformation>FedRAMP will continue to work with our counterparts across the government at NIST, DHS, and OMB and through government councils like the CIOC and ISIMC to ensure the program's work continues to align with other IT initiatives and contribute to a more cohesive cybersecurity framework across government.</OtherInformation></Objective></Goal></StrategicPlanCore><AdministrativeInformation><StartDate>2014-12-17</StartDate><EndDate/><PublicationDate>2015-02-23</PublicationDate><Source>https://cloud.cio.gov/sites/default/files/documents/files/FedRAMP%20Forward%202%20Year%20Priorities.pdf</Source></AdministrativeInformation><Submitter><FirstName>Owen</FirstName><LastName>Ambur</LastName><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></PerformancePlanOrReport>