Reference

GRC Basics

The terms that matter in information security, compliance, and data protection. Definitions written for practitioners, with context that makes them useful in real assessments.

44 terms

Core Concepts

8

Governance

NIST CSF 2.0ISO 27001CMMC
Core Concepts

The policies, decision-making structures, and accountability mechanisms an organization uses to direct and oversee its information security program.

Governance answers who decides, who is accountable, and how security objectives connect to business objectives. In NIST CSF 2.0, the new GOVERN function made governance an explicit requirement rather than an implied one. When an assessor asks about governance, they want to see documented policies signed by leadership, defined roles, and evidence that security decisions reach the board level.

Risk

ISO 27001NIST CSF 2.0HIPAAFedRAMP
Core Concepts

The potential for a threat to exploit a vulnerability and cause harm to an asset, expressed as a combination of likelihood and impact.

Risk is not the same as a vulnerability or a threat. A vulnerability is a weakness. A threat is something that could exploit it. Risk is the combination of how likely that exploitation is and how bad the result would be. Formal risk assessments quantify this on a scale, usually 1 to 5 for both axes, producing an inherent risk rating before controls and a residual risk rating after controls are applied.

Compliance

Core Concepts

The state of meeting the requirements of an applicable law, regulation, standard, or contractual obligation.

Compliance and security are not the same thing. An organization can be compliant and insecure, or secure and non-compliant. Compliance is a point-in-time determination against a defined set of requirements. Security is an ongoing operational posture. In practice, the compliance program should be designed to produce genuine security outcomes, not just pass an audit.

Control

ISO 27001SOC 2CMMCFedRAMP
Core Concepts

A safeguard or countermeasure designed to reduce risk by preventing, detecting, or correcting an undesirable event.

Controls are the building blocks of every compliance framework. ISO 27001 Annex A lists 93 controls. NIST 800-171 lists 110 practices. SOC 2 has Trust Services Criteria. Every one of these is a control. Controls are classified as preventive (stopping an event), detective (identifying an event after it occurs), or corrective (recovering from an event). An assessor evaluates whether your controls exist, are designed correctly, and are operating effectively.

Finding

Core Concepts

A documented deficiency identified during an assessment where a control does not meet its stated requirement.

Findings come in severity levels. In most frameworks: Critical or High findings indicate a significant gap that cannot be deferred. Moderate findings indicate a meaningful gap with a defined remediation timeline. Low findings are minor deficiencies. In FedRAMP, findings are rated by CVSS score for technical vulnerabilities. In CMMC, any practice that is Not Met is a finding. In SOC 2, a finding during a Type II report becomes an exception in the auditor's report.

Gap

Core Concepts

The difference between an organization's current implementation of a control and the requirement that control must meet.

A gap analysis is typically the first structured activity in any compliance engagement. It maps current state against each requirement and identifies what is missing. Gaps are then prioritized by risk impact and remediation effort. Not all gaps are equal. A gap in MFA for privileged accounts carries far more risk than a gap in clean desk policy documentation.

Residual Risk

ISO 27001FedRAMPNIST CSF 2.0
Core Concepts

The risk that remains after controls have been applied to reduce inherent risk.

No control eliminates risk entirely. Residual risk is what you accept after implementing your chosen controls. Every framework requires that residual risk be formally accepted by someone with the authority to do so. In ISO 27001, the risk owner accepts residual risk. In FedRAMP, the Authorizing Official accepts residual risk as part of granting the ATO. Undocumented residual risk is one of the most common findings in formal assessments.

Compensating Control

PCI DSSCMMCFedRAMP
Core Concepts

An alternative control implemented when the standard requirement cannot be met exactly as written, designed to provide equivalent risk reduction.

Not every environment can implement every requirement as specified. Legacy systems, operational constraints, and cost can make exact compliance technically infeasible. A compensating control must address the same risk as the original requirement and provide equivalent or better protection. In PCI DSS, compensating controls require formal documentation and QSA approval. CMMC allows compensating controls in some cases but not for the most critical practices like MFA.

Data Classification

5

CUI

Controlled Unclassified Information
CMMCFedRAMP
Data Classification

Information the U.S. government creates or possesses, or that an entity creates or possesses on behalf of the government, that requires safeguarding per law, regulation, or policy.

CUI is the trigger for CMMC. If your organization handles CUI under a DoD contract, CMMC Level 2 applies. CUI is not classified information, but it is sensitive. Examples include technical drawings, engineering specifications, personally identifiable information in federal systems, legal privilege, and law enforcement sensitive information. The National Archives CUI Registry lists all authorized CUI categories. Organizations must identify where CUI lives in their environment before scoping a CMMC assessment.

FCI

Federal Contract Information
CMMC
Data Classification

Information provided by or generated for the U.S. government under a contract to develop or deliver a product or service to the government, not intended for public release.

FCI triggers CMMC Level 1. It is a broader category than CUI. All CUI is FCI, but not all FCI is CUI. A company that makes physical components for a government facility handles FCI. If those components involve controlled technical specifications, those specifications are CUI as well. The distinction matters because Level 1 requires only 17 basic practices, while Level 2 requires all 110 NIST 800-171 practices.

PHI

Protected Health Information
HIPAA
Data Classification

Individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or business associate, in any format.

PHI is defined by 18 specific identifiers. If health information includes any of these identifiers, it is PHI and HIPAA applies. The identifiers include names, geographic data smaller than state, dates except year, phone numbers, email addresses, Social Security numbers, medical record numbers, and device identifiers, among others. De-identification requires removing all 18 identifiers or applying a statistical method. Electronic PHI transmitted or stored in digital form is called ePHI and is subject to the Security Rule.

Personal Data

GDPRDPDPA
Data Classification

Any information relating to an identified or identifiable natural person. An identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, number, location, or online identifier.

This is the GDPR definition. The key word is identifiable. Even pseudonymized data can be personal data if it can be re-identified using a key held by the controller. IP addresses are personal data. Cookie identifiers are personal data. Hashed email addresses may be personal data if the controller can reverse the hash. The DPDPA uses the term personal data in a similarly broad sense for Indian law. Both regulations distinguish between regular personal data and sensitive personal data, which carries stricter requirements.

Cardholder Data

PCI DSS
Data Classification

The full primary account number (PAN) of a payment card, along with the cardholder name, service code, and expiration date when stored in conjunction with the PAN.

PCI DSS applies wherever cardholder data or sensitive authentication data is stored, processed, or transmitted. The cardholder data environment (CDE) is the scope of a PCI DSS assessment. Reducing scope by isolating, not storing, or tokenizing cardholder data is the most effective way to reduce PCI DSS compliance burden. Sensitive authentication data, which includes the full track data, CVV2, and PIN block, cannot be stored after authorization under any circumstance.

Assessment Process

8

Assessment Objective

AO
CMMCFedRAMP
Assessment Process

A specific testable statement derived from a security requirement that an assessor evaluates to determine whether a control is implemented correctly and operating effectively.

NIST 800-171A defines assessment objectives for each of the 110 NIST 800-171 practices. Each practice has multiple AOs, bringing the total to 320 in the CMMC context. An SSP narrative must address every AO for each practice it covers. If the narrative describes what the organization does but does not address a specific AO, that AO is a gap. Assessors evaluate AOs through three methods: examine (review documentation), interview (question personnel), and test (technical verification).

System Security Plan

SSP
CMMCFedRAMPISO 27001
Assessment Process

A formal document that describes the security requirements of an information system and the controls in place or planned to meet those requirements.

The SSP is the central artifact of any formal security assessment. In FedRAMP, the SSP can run 300 to 500 pages for a Moderate system. In CMMC, it is the document auditors read before fieldwork begins. Every implementation narrative must be written in present tense, be specific to the actual system, name the tools and processes in use, and address every assessment objective. A narrative that describes what the organization plans to do, rather than what it does, is not a compliant SSP entry.

Plan of Action and Milestones

POA&M
CMMCFedRAMPNIST CSF 2.0
Assessment Process

A document that identifies tasks needed to remediate security weaknesses, assigns responsibility, establishes milestone dates, and tracks progress toward remediation.

A POA&M is not an excuse to defer every gap indefinitely. In CMMC, certain practices cannot be placed on a POA&M at all. They must be implemented before assessment. In FedRAMP, POA&M items have defined SLA timelines based on severity: Critical within 30 days, High within 30 days, Moderate within 90 days, Low within 180 days. Agencies review POA&M status as part of continuous monitoring. An aging POA&M with no progress is a major finding.

Statement of Applicability

SoA
ISO 27001
Assessment Process

A document that lists all controls from a standard's control set, states whether each control is applicable to the organization, provides a justification for any exclusions, and describes how applicable controls are implemented.

The SoA is the first document an ISO 27001 auditor reads. Every exclusion in the SoA will be examined. If you exclude A.8.23 Web Filtering, the auditor will ask why. If you exclude A.7.4 Physical Security Monitoring, they will want to understand the business justification. Exclusions are legitimate when a control genuinely does not apply. They are not acceptable when the control applies but is difficult to implement.

Evidence Artifact

Assessment Process

A document, log, screenshot, configuration file, or record that demonstrates a control is in place and operating as described.

Assessors distinguish between policy existence (the document says we do this) and operational evidence (here is proof we did this). A security awareness training policy is not evidence of training. Training completion records, dated attendance logs, and quiz scores are evidence. For a SOC 2 Type II report covering 12 months, you need evidence that covers the entire period, not just the week before the audit. Evidence must be dated, specific, and traceable to the control being tested.

Scope

CMMCFedRAMPPCI DSSSOC 2
Assessment Process

The defined boundary of systems, people, processes, and facilities included in an assessment or certification.

Scope defines what gets assessed. Everything inside the scope boundary must meet the applicable requirements. Everything outside the scope must be genuinely isolated from in-scope systems or it falls within scope by proximity. Scoping decisions made too broadly increase cost and effort. Scoping decisions made too narrowly get challenged during assessment when assessors find systems that touch in-scope data but were excluded. Scope is set before assessment begins and documented in the SSP or System Description.

Continuous Monitoring

ConMon
FedRAMPCMMCISO 27001NIST CSF 2.0
Assessment Process

The ongoing assessment of security controls to maintain awareness of the security posture of an information system and identify changes that affect security.

In FedRAMP, continuous monitoring is a formal program with monthly deliverables: vulnerability scan results, updated POA&M, and change request status. In CMMC, continuous monitoring refers to the ongoing operational effectiveness of controls between triennial assessments. In ISO 27001, it is addressed through internal audits and management reviews. Regulators treat gaps in continuous monitoring as seriously as gaps in initial implementation, because they indicate a compliance theater program rather than genuine security operations.

Risk Assessment

ISO 27001HIPAAFedRAMPNIST CSF 2.0
Assessment Process

A structured process to identify potential threats to an information system, evaluate the likelihood and impact of each threat, and determine the level of risk to organizational operations.

Every major framework requires a formal risk assessment. HIPAA's Security Rule mandates it as a Required specification. ISO 27001 Clause 6.1 requires it before building the ISMS. FedRAMP requires it as part of the SSP. A risk assessment is not a vulnerability scan. A vulnerability scan identifies technical weaknesses in systems. A risk assessment evaluates threats to the organization's assets, considers existing controls, and produces a risk register with prioritized remediation recommendations.

People and Roles

8

Covered Entity

HIPAA
People and Roles

Under HIPAA, a health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically in connection with a covered transaction.

Covered entities have direct obligations under HIPAA. They must comply with both the Privacy Rule and the Security Rule. The most common covered entities are hospitals, physician practices, health plans (insurance companies), and healthcare clearinghouses (entities that process claims). Covered entities are responsible for their own compliance and for ensuring that any vendor they share PHI with has a signed Business Associate Agreement.

Business Associate

BA
HIPAA
People and Roles

A person or entity that performs functions or activities on behalf of a covered entity that involves the use or disclosure of protected health information.

Business associates became directly liable under HIPAA through the HITECH Act and the 2013 Omnibus Rule. Before that change, only covered entities were directly regulated. Now, a cloud provider storing ePHI for a hospital is itself a business associate with direct HIPAA obligations, not just a contractual obligation to the hospital. Examples include billing companies, IT service providers, cloud platforms, consultants with PHI access, and legal firms representing a covered entity.

Data Fiduciary

DPDPA
People and Roles

Under India's DPDPA 2023, any person who alone or in conjunction with others determines the purpose and means of processing of personal data.

Data Fiduciary is the DPDPA equivalent of Controller under GDPR. The obligations on a Data Fiduciary include providing notice before processing, obtaining consent, ensuring data accuracy, implementing security safeguards, notifying the Data Protection Board of breaches, and erasing data when the purpose is fulfilled. Significant Data Fiduciaries, designated by the Central Government based on data volume and sensitivity, have additional obligations including appointing an India-based DPO.

Data Principal

DPDPA
People and Roles

Under India's DPDPA 2023, the individual to whom personal data relates.

Data Principal is the DPDPA equivalent of Data Subject under GDPR. Data Principals have rights including the right to information about processing, the right to correction and erasure, and the right to grievance redressal. Unlike GDPR, the DPDPA also places duties on Data Principals, including not impersonating others, not suppressing material information, and not making frivolous complaints. This is unique among major data protection laws.

C3PAO

Certified Third-Party Assessment Organization
CMMC
People and Roles

An organization accredited by the CMMC Accreditation Body to conduct official CMMC Level 2 assessments for defense contractors.

C3PAOs must be accredited by the Cyber AB, the CMMC Accreditation Body. They employ Certified CMMC Assessors who conduct fieldwork, and a Certified CMMC Professional who manages the engagement. C3PAO assessments follow a defined methodology: document review, personnel interviews, and technical testing. The assessment results go into the government's eMASS system. Choosing a C3PAO is consequential. Ask for their experience in your industry, the lead assessor's credentials, and their average finding rate.

3PAO

Third Party Assessment Organization
FedRAMP
People and Roles

An independent organization accredited by A2LA under ISO/IEC 17020 to conduct FedRAMP security assessments for cloud service providers.

3PAOs produce the Security Assessment Report that becomes the primary input to the Authorization to Operate decision. They must be independent from the cloud provider being assessed. A 3PAO that also provides consulting services to the same provider for the same system creates a conflict of interest that the FedRAMP Program Management Office will challenge. The A2LA accreditation must be current at the time of assessment.

QSA

Qualified Security Assessor
PCI DSS
People and Roles

An individual certified by the PCI Security Standards Council to conduct PCI DSS assessments for Level 1 merchants and service providers.

QSAs work for QSA Companies, which are independently certified by the PCI SSC. Only QSAs can issue Reports on Compliance for Level 1 merchants. Level 2 through Level 4 merchants may use Self-Assessment Questionnaires without a QSA. QSAs are not interchangeable. They have areas of specialization. A QSA experienced in retail POS environments may not be the right choice for a cloud-based payment processor. Verify their experience with your specific environment type.

Data Protection Officer

DPO
GDPRDPDPA
People and Roles

An individual designated to oversee an organization's data protection strategy and ensure compliance with data protection laws, required in certain circumstances by GDPR and DPDPA.

Under GDPR, a DPO is mandatory for public authorities, organizations that carry out large-scale systematic monitoring of individuals, and organizations that process special categories of data at scale. The DPO must have expert knowledge of data protection law and cannot be given instructions on how to perform their tasks. Under DPDPA, Significant Data Fiduciaries must appoint a DPO who is based in India and is a Key Managerial Person of the fiduciary.

Authorization

3

Authorization to Operate

ATO
FedRAMP
Authorization

An official management decision by an Authorizing Official to authorize operation of an information system, accepting any residual risk based on the implemented security controls.

An ATO is not a certification. It is a risk acceptance decision made by a named official who is accountable for that decision. In FedRAMP, the Authorizing Official is typically a federal agency CIO or CISO. The ATO is based on the 3PAO Security Assessment Report, the SSP, the POA&M, and any agency-specific requirements. ATOs are time-limited, typically three years, and require continuous monitoring to maintain. A significant change to the system boundary requires notifying the authorizing agency and may require re-assessment.

SPRS Score

Supplier Performance Risk System Score
CMMC
Authorization

A numerical score from negative 203 to positive 110 representing a defense contractor's implementation of the 110 NIST 800-171 Rev 2 practices, submitted to the DoD's Supplier Performance Risk System.

The SPRS score starts at 110. Each NIST 800-171 practice has an assigned point value of 1, 3, or 5. If a practice is Not Met, that value is deducted. A score of 110 means all practices are implemented. A score below 110 indicates gaps. DoD contracting officers can view SPRS scores and use them in source selection. Contractors self-attest their SPRS score. Under CMMC 2.0, assessments by C3PAOs will verify self-assessed scores. A materially inaccurate SPRS score can result in False Claims Act liability.

Certification vs Attestation

ISO 27001SOC 2FedRAMP
Authorization

Certification is a formal declaration by an independent third party that an organization meets a specific standard. Attestation is a formal declaration by management that controls are in place, validated by an independent practitioner.

ISO 27001 produces a certificate. SOC 2 produces an attestation report. This is not a minor semantic difference. A certificate says the third party examined the controls and found them compliant. An attestation says management asserts the controls are in place and the CPA has examined the evidence and found no material exceptions. Enterprise customers in procurement increasingly distinguish between the two. Some contracts specifically require ISO 27001 certification rather than a SOC 2 report, and vice versa.

Technical

8

Multi-Factor Authentication

MFA
CMMCPCI DSSFedRAMPISO 27001
Technical

An authentication method that requires a user to provide two or more verification factors from different categories: something you know, something you have, or something you are.

MFA is one of the most consistently required controls across every major framework. CMMC practice 3.5.3 requires MFA for local and network access to systems containing CUI, and it cannot be placed on a POA&M. PCI DSS v4.0 expanded MFA requirements significantly, now requiring it for all access into the CDE, not just remote access. NIST 800-63B provides the technical definition of authentication assurance levels. Two SMS messages sent to the same phone are not MFA. A password plus an SMS code is MFA. A password plus a hardware token is stronger MFA.

Encryption at Rest

CMMCHIPAAFedRAMP
Technical

The encryption of data stored on a physical medium, such as a hard drive, database, or backup tape, so that it cannot be read without the decryption key.

Encryption at rest protects against physical theft and unauthorized access to storage media. It is required by multiple frameworks. CMMC practice 3.13.16 requires protection of CUI at rest. HIPAA Technical Safeguard 164.312(a)(2)(iv) recommends encryption as an addressable specification. If you encrypt PHI at rest using NIST-approved methods, a breach of that data may not trigger HIPAA breach notification. FIPS 140-2 or FIPS 140-3 validated encryption is required for CUI under CMMC and for data in FedRAMP systems.

Encryption in Transit

CMMCFedRAMPPCI DSSHIPAA
Technical

The encryption of data as it moves between systems over a network, ensuring it cannot be intercepted and read during transmission.

TLS 1.2 or higher is the current minimum standard for encryption in transit across most frameworks. TLS 1.0 and 1.1 are deprecated and will be flagged as findings. In FedRAMP, SC-8 requires cryptographic protection for data in transit. In CMMC, practice 3.13.8 covers this. The implementation must include proper certificate validation. Turning off certificate checking for convenience, even in internal systems, is a finding. FIPS-validated cryptography applies to the cipher suites used, not just the protocol version.

FIPS 140

CMMCFedRAMP
Technical

Federal Information Processing Standard 140, a U.S. government standard that defines security requirements for cryptographic modules used to protect sensitive information.

FIPS 140-2 is the current widely referenced version. FIPS 140-3 became effective in September 2022 and is the current version for new validations. CMMC practice 3.13.11 requires FIPS-validated cryptography for CUI, and it cannot be placed on a POA&M. This means the encryption library or module used must be on the NIST Cryptographic Module Validation Program (CMVP) validated modules list. Using a strong algorithm like AES-256 is not sufficient by itself. The implementation library must be validated. OpenSSL FIPS module, Windows CNG, and AWS GovCloud cryptographic services are examples of validated implementations.

Vulnerability

CMMCFedRAMPPCI DSSISO 27001
Technical

A weakness in a system, software, or process that could be exploited by a threat actor to gain unauthorized access or cause harm.

Vulnerability is not the same as risk. A vulnerability exists in isolation. Risk requires both a vulnerability and a threat that could exploit it. Vulnerabilities are identified through vulnerability scanning (automated tools like Tenable, Qualys, Rapid7) and manual penetration testing. CVE (Common Vulnerabilities and Exposures) identifiers and CVSS (Common Vulnerability Scoring System) scores provide a standard language for describing and prioritizing vulnerabilities. Most frameworks require regular vulnerability scanning: CMMC requires it per practice 3.11.2, FedRAMP per CA-7 and RA-5.

Zero Trust

FedRAMPCMMCNIST CSF 2.0
Technical

A security model based on the principle that no user, device, or network segment should be trusted by default, requiring continuous verification of identity and authorization for every access request.

Zero Trust is not a product or a single control. It is a design philosophy applied across identity, device, network, application, and data layers. NIST SP 800-207 defines Zero Trust Architecture. DoD's Zero Trust Strategy mandates implementation across defense systems. In CMMC and FedRAMP contexts, Zero Trust principles translate to specific controls: micro-segmentation of networks, just-in-time privileged access, continuous endpoint validation, and strong identity verification before every access request. Implementing Zero Trust does not substitute for meeting the specific control requirements of CMMC or FedRAMP.

SIEM

Security Information and Event Management
FedRAMPCMMCCERT-In
Technical

A system that aggregates log data from across an IT environment, correlates events, and generates alerts for anomalous or potentially malicious activity.

Most formal frameworks require centralized log management and alerting, which a SIEM satisfies. In FedRAMP, SI-4 (Information System Monitoring) and AU-6 (Audit Record Review) drive the SIEM requirement. In CMMC, practice 3.14.6 (monitor systems to detect attacks) and 3.3.5 (correlate audit record review) point to the same need. CERT-In's 180-day log retention requirement necessitates a log management system with sufficient storage. For organizations in India, logs must be stored within India, which affects cloud-hosted SIEM choices.

Penetration Testing

PCI DSSFedRAMPISO 27001
Technical

A simulated cyberattack conducted by authorized security professionals to identify exploitable vulnerabilities in a system before malicious actors do.

Penetration testing is distinct from vulnerability scanning. A scan identifies known vulnerabilities automatically. A penetration test involves a human attempting to exploit those vulnerabilities in the way an attacker would. PCI DSS Requirement 11.4 mandates penetration testing at least annually and after significant changes. FedRAMP requires penetration testing as part of the initial 3PAO assessment and annually thereafter. CMMC does not mandate penetration testing explicitly, but assessors may conduct technical testing as part of fieldwork. The scope, methodology, and rules of engagement must be documented before any penetration test begins.

Contracts and Agreements

4

Business Associate Agreement

BAA
HIPAA
Contracts and Agreements

A contract required by HIPAA between a covered entity and a business associate that establishes the permitted uses and disclosures of PHI and the BA's obligations to protect it.

A BAA is not optional. If a vendor touches PHI and there is no signed BAA, both parties are in violation of HIPAA. The BAA must include specific elements enumerated in 45 CFR 164.504(e): permitted uses and disclosures, prohibitions on other uses, required safeguards, reporting of breaches, and return or destruction of PHI at termination. Signing a BAA does not transfer liability to the vendor. Both parties remain liable for their own violations. BAAs must also address subcontractors, which are sub-processors in GDPR language.

Data Processing Agreement

DPA
GDPR
Contracts and Agreements

A contract required by GDPR between a data controller and a data processor that governs how the processor handles personal data on behalf of the controller.

Article 28 of GDPR mandates a DPA for every controller-processor relationship involving EU personal data. The DPA must specify the subject matter, duration, nature, and purpose of processing, the type of personal data, the categories of data subjects, and the rights and obligations of the controller. Without a DPA, the controller is in violation of Article 28, which can result in fines regardless of whether any data breach occurred. Standard Contractual Clauses can serve as the DPA for international transfers in some situations.

Standard Contractual Clauses

SCCs
GDPR
Contracts and Agreements

Pre-approved contractual clauses issued by the European Commission that provide an adequate legal mechanism for transferring personal data from the EU to third countries lacking an adequacy decision.

SCCs are the most widely used mechanism for EU-to-third-country data transfers since Privacy Shield was invalidated by Schrems II in 2020. The European Commission issued new SCCs in June 2021. They come in four modules: controller to controller, controller to processor, processor to processor, and processor to controller. Organizations must select the correct module, complete the annexes with specifics about the data transfer, and conduct a Transfer Impact Assessment to determine whether the destination country's laws undermine the SCCs' protections.

Interconnection Security Agreement

ISA
FedRAMPCMMC
Contracts and Agreements

A formal agreement between organizations that connect their IT systems, documenting the security requirements, responsibilities, and controls governing the connection.

ISAs are required in FedRAMP when an authorized system connects to an external system. They document what data flows between systems, what security controls protect the connection, and who is responsible for each control. An ISA is required even when connecting to another FedRAMP-authorized system. The absence of an ISA for a documented external connection is a finding during 3PAO assessment. ISAs are also referenced in CMMC for connections to external systems under practice 3.1.20.

Definitions are based on the official publications of the relevant issuing bodies. Practitioner context reflects real assessment and implementation experience across these frameworks.