|
2656 | 2656 | "PVA-CSX-RAD": { |
2657 | 2657 | "fka": "FRR-PVA-08", |
2658 | 2658 | "name": "Receiving Advice", |
2659 | | - "statement": "Providers MAY ask for and accept advice from their assessor during assessment regarding techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their validation and reporting procedures for Key Security Indicators, UNLESS doing so might compromise the objectivity and integrity of the assessment (see also PVA-TPX-AMA).", |
| 2659 | + "statement": "Providers MAY ask for and accept advice from their assessor during assessment regarding techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their validation and reporting procedures for Key Security Indicators, UNLESS doing so might compromise the objectivity and integrity of the assessment (see also PVA-TPX-SHA).", |
2660 | 2660 | "affects": ["Providers"], |
2661 | 2661 | "primary_key_word": "MAY", |
2662 | 2662 | "note": "The related A2LA requirements are waived for FedRAMP 20x Phase Two assessments.", |
2663 | 2663 | "updated": [ |
| 2664 | + { |
| 2665 | + "date": "2026-02-09", |
| 2666 | + "comment": "Fixed incorrect reference to old FRR by changing PVA-TPX-AMA to PVA-TPX-SHA; no material changes." |
| 2667 | + }, |
2664 | 2668 | { |
2665 | 2669 | "date": "2026-02-04", |
2666 | 2670 | "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
|
2807 | 2811 | "PVA-TPX-SHA": { |
2808 | 2812 | "fka": "FRR-PVA-09", |
2809 | 2813 | "name": "Sharing Advice", |
2810 | | - "statement": "Assessors MAY share advice with providers they are assessing about techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their validation and reporting procedures for Key Security Indicators, UNLESS doing so might compromise the objectivity and integrity of the assessment (see also PVA-CSX-RIA).", |
| 2814 | + "statement": "Assessors MAY share advice with providers they are assessing about techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their validation and reporting procedures for Key Security Indicators, UNLESS doing so might compromise the objectivity and integrity of the assessment (see also PVA-CSX-RAD).", |
2811 | 2815 | "affects": ["Assessors"], |
2812 | 2816 | "primary_key_word": "MAY", |
2813 | 2817 | "updated": [ |
| 2818 | + { |
| 2819 | + "date": "2026-02-09", |
| 2820 | + "comment": "Fixed incorrect reference to old FRR by changing PVA-CSX-RIA to PVA-CSX-RAD; no material changes." |
| 2821 | + }, |
2814 | 2822 | { |
2815 | 2823 | "date": "2026-02-04", |
2816 | 2824 | "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
|
0 commit comments