Fully Mitigated Vulnerability
Also: fully mitigated vulnerability, fully mitigated vulnerabilities, fully mitigate vulnerabilities
Definition
Verbatim from FedRAMP/rules
A vulnerability where the likelihood of exploitation or Potential Agency Impact N-rating has been reduced from the original evaluation until either are negligible, but the vulnerability is still detected.
Used in 3 rule requirements
This term is a defined part of the following FedRAMP rule requirements — when it appears in a rule, this definition applies precisely.
Change history
2026-07-04Initial reset for the Consolidated Rules for 2026 Public Preview.