[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-167068-en":3,"doc-seo-167068-105":30,"detail-sidebar-cat-1-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":11,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":15,"update_tm":28,"read_time":29},167068,2336475104736,"วิน","https://ap-avatar.wpscdn.com/avatar/22000c4c5e0e5b17e70?x-image-process=image/resize,m_fixed,w_180,h_180&k=1786591360781797222",1,11,"Presentations","FedRAMP Annual Security Assessment Plan (SAP) Template - Version - Month/Year","FedRAMP Annual Security Assessment Plan (SAP) Template provides a structured blueprint for conducting a cloud service provider’s annual security assessment. It defines purpose, scope, applicable laws and regulations, relevant standards and FedRAMP guidance, and details the assessment methodology. The plan includes testing approach, security assessment team roles, CSP points of contact, automated and manual testing procedures, schedules, and rules of engagement covering disclosures, communications, and signatures. Appendices support acronyms and test case procedures.","FedRAMP Annual Security Assessment Plan (SAP) Template\nVersion #.#\nMonth xx, xxxx\n\u000f\nPrepared by\nPrepared for\n\u000f\nTemplate Revision History\n\u000f\nTable of Contents\n\u0013 TOC \\o \"2-2\" \\h \\z \\t \"Heading 1,1,GSA Title-YES for TOC,1,GSA Subsection,2,GSA Section,1,GSA subsection2,3\" \u0014\u0013 HYPERLINK \\l \"_Toc389750915\" \u0014Template Revision History\t\u0013 PAGEREF _Toc389750915 \\h \u00143\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750916\" \u0014About this document\t\u0013 PAGEREF _Toc389750916 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750917\" \u0014Who should use this document?\t\u0013 PAGEREF _Toc389750917 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750918\" \u0014How this document is organized\t\u0013 PAGEREF _Toc389750918 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750919\" \u0014How to contact us\t\u0013 PAGEREF _Toc389750919 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750920\" \u00141. Overview\t\u0013 PAGEREF _Toc389750920 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750921\" \u00141.1. Purpose\t\u0013 PAGEREF _Toc389750921 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750922\" \u00141.2. Applicable Laws and Regulations\t\u0013 PAGEREF _Toc389750922 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750923\" \u00141.3. Applicable Standards and Guidance\t\u0013 PAGEREF _Toc389750923 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750924\" \u00141.4. Fedramp Requirements and Guidance\t\u0013 PAGEREF _Toc389750924 \\h \u00149\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750925\" \u00142. Scope\t\u0013 PAGEREF _Toc389750925 \\h \u00149\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750926\" \u00142.1. System Name/Title\t\u0013 PAGEREF _Toc389750926 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750927\" \u00142.2. IP Addresses Slated for Testing\t\u0013 PAGEREF _Toc389750927 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750928\" \u00142.3. Web Applications Slated for Testing\t\u0013 PAGEREF _Toc389750928 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750929\" \u00142.4. Databases Slated for Testing\t\u0013 PAGEREF _Toc389750929 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750930\" \u00142.5. Roles Slated for Testing\t\u0013 PAGEREF _Toc389750930 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750931\" \u00143. Assumptions\t\u0013 PAGEREF _Toc389750931 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750932\" \u00144. Methodology\t\u0013 PAGEREF _Toc389750932 \\h \u001413\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750933\" \u00145. Test Plan\t\u0013 PAGEREF _Toc389750933 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750934\" \u00145.1. Security Assessment Team\t\u0013 PAGEREF _Toc389750934 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750935\" \u00145.2. CSP Testing Points of Contact\t\u0013 PAGEREF _Toc389750935 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750936\" \u00145.3. Testing Performed Using Automated Tools\t\u0013 PAGEREF _Toc389750936 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750937\" \u00145.4. Testing Performed through Manual Methods\t\u0013 PAGEREF _Toc389750937 \\h \u001415\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750938\" \u00145.5. Schedule\t\u0013 PAGEREF _Toc389750938 \\h \u001416\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750939\" \u00146. Rules of Engagement\t\u0013 PAGEREF _Toc389750939 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750940\" \u00146.1. Disclosures\t\u0013 PAGEREF _Toc389750940 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750941\" \u00146.1.1. Security Testing May Include\t\u0013 PAGEREF _Toc389750941 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750942\" \u00146.1.2. Security Testing Will Not Include\t\u0013 PAGEREF _Toc389750942 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750943\" \u00146.2. End of Testing\t\u0013 PAGEREF _Toc389750943 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750944\" \u00146.3. Communication of Test Results\t\u0013 PAGEREF _Toc389750944 \\h \u001418\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750945\" \u00146.4. Limitation of Liability\t\u0013 PAGEREF _Toc389750945 \\h \u001419\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750946\" \u00146.5. Signatures\t\u0013 PAGEREF _Toc389750946 \\h \u001419\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750947\" \u0014Appendix A – Acronyms\t\u0013 PAGEREF _Toc389750947 \\h \u001420\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750948\" \u0014Appendix B – Test Case Procedures\t\u0013 PAGEREF _Toc389750948 \\h \u001421\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750949\" \u0014Appendix C – Attachments\t\u0013 PAGEREF _Toc389750949 \\h \u001422\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389750950\" \u0014Appendix D – Penetration Testing Plan and Methodology\t\u0013 PAGEREF _Toc389750950 \\h \u001423\u0015\u0015\n\u0015\u000f\nList of Tables\n\u0013 TOC \\h \\z \\t \"GSA Table Caption\" \\c \u0014\u0013 HYPERLINK \\l \"_Toc389643444\" \u0014Table 2-1 – Information System Name and Title\t\u0013 PAGEREF _Toc389643444 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389643445\" \u0014Table 2-2 – Location of Components\t\u0013 PAGEREF _Toc389643445 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389643446\" \u0014Table 2-3 – Components Slated for Testing\t\u0013 PAGEREF _Toc389643446 \\h \u001411\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc389","cbCaiea3cEOZI29Z","https://ap.wps.com/l/cbCaiea3cEOZI29Z","docx",340973,23,"English","en",105,"# 1. Overview\n## 1.1 Purpose\n## 1.2 Applicable Laws and Regulations\n## 1.3 Applicable Standards and Guidance\n## 1.4 Fedramp Requirements and Guidance\n# 2. Scope\n## 2.1 System Name/Title\n## 2.2 IP Addresses Slated for Testing\n## 2.3 Web Applications Slated for Testing\n## 2.4 Databases Slated for Testing\n## 2.5 Roles Slated for Testing\n# 3. Assumptions\n# 4. Methodology\n# 5. Test Plan\n## 5.1 Security Assessment Team\n## 5.2 CSP Testing Points of Contact\n## 5.3 Testing Performed Using Automated Tools\n## 5.4 Testing Performed through Manual Methods\n## 5.5 Schedule\n# 6. Rules of Engagement\n## 6.1 Disclosures\n## 6.2 End of Testing\n## 6.3 Communication of Test Results\n## 6.4 Limitation of Liability\n## 6.5 Signatures\n# Appendix A – Acronyms\n# Appendix B – Test Case Procedures\n# Appendix C – Attachments\n# Appendix D – Penetration Testing Plan and Methodology","[{\"question\":\"Who is this FedRAMP annual SAP template intended for?\",\"answer\":\"The document is intended to be used by Independent Assessors (IAs) when testing Cloud Service Provider (CSP) security controls.\"},{\"question\":\"What are the main sections included in the template?\",\"answer\":\"The template is organized into six main sections and three appendices, covering overview, scope, assumptions, methodology, the test plan, and rules of engagement.\"},{\"question\":\"How does the template handle security testing execution and coordination?\",\"answer\":\"It specifies the security assessment team, CSP points of contact, testing performed using automated tools and manual methods, along with a schedule and rules of engagement for disclosures and communication of test results.\"}]","FedRAMP Annual Security Assessment Plan (SAP) Template - Version - Month/Year | DOCX",1788207584,8,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":14,"keywords":34,"description":15,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"fedramp-annual-security-assessment-plan-sap-template-version-monthyear","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/template/","Template",2,{"item":49,"name":13,"@type":43,"position":50},"https://docshare.wps.com/template/presentations/",3,{"item":52,"name":14,"@type":43,"position":53},"https://docshare.wps.com/template/fedramp-annual-security-assessment-plan-sap-template-version-monthyear/167068/",4,{"url":52,"name":14,"@type":55,"author":56,"headline":14,"publisher":58,"fileFormat":61,"inLanguage":23,"description":15,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-02","2026-08-31",true,{"@type":66,"interactionType":67,"userInteractionCount":11},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Who is this FedRAMP annual SAP template intended for?","Question",{"text":76,"@type":77},"The document is intended to be used by Independent Assessors (IAs) when testing Cloud Service Provider (CSP) security controls.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What are the main sections included in the template?",{"text":81,"@type":77},"The template is organized into six main sections and three appendices, covering overview, scope, assumptions, methodology, the test plan, and rules of engagement.",{"name":83,"@type":74,"acceptedAnswer":84},"How does the template handle security testing execution and coordination?",{"text":85,"@type":77},"It specifies the security assessment team, CSP points of contact, testing performed using automated tools and manual methods, along with a schedule and rules of engagement for disclosures and communication of test results.","https://schema.org",{"og:url":52,"og:type":88,"og:title":14,"og:site_name":59,"og:description":15},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,97,102,107,112,117,122,127,132],{"id":12,"doc_module":11,"doc_module_name":46,"category_name":13,"show_sort_weight":95,"slug":96},90,"presentations",{"id":98,"doc_module":11,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},12,"Resumes",80,"resumes",{"id":103,"doc_module":11,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},14,"Invoices",70,"invoices",{"id":108,"doc_module":11,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},15,"Posters",60,"posters",{"id":113,"doc_module":11,"doc_module_name":46,"category_name":114,"show_sort_weight":115,"slug":116},16,"Social Media",50,"social-media",{"id":118,"doc_module":11,"doc_module_name":46,"category_name":119,"show_sort_weight":120,"slug":121},17,"Forms",40,"forms",{"id":123,"doc_module":11,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},18,"Letters",30,"letters",{"id":128,"doc_module":11,"doc_module_name":46,"category_name":129,"show_sort_weight":130,"slug":131},21,"Paper Templates",5,"papers-templates",{"id":133,"doc_module":11,"doc_module_name":46,"category_name":134,"show_sort_weight":4,"slug":135},158,"General","general-158"]