Vulnerability
Also: vulnerability, vulnerabilities
Definition
Verbatim from FedRAMP/rules
Has the meaning given to "security vulnerability" in 6 USC § 650 (25), which is "any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of [...] management, operational, and technical controls used to protect against an unauthorized effort to adversely affect the confidentiality, integrity, and availability of an information system or its information." This includes gaps in Rev5 Controls and 20x Key Security Indicators, software vulnerabilities, misconfigurations, exposures, weak credentials, insecure services, and all other such potential weaknesses in protection (intentional or unintentional).
Used in 42 rule requirements
This term is a defined part of the following FedRAMP rule requirements — when it appears in a rule, this definition applies precisely.
CCM-OCR-AVLFRC-CLA-MFRFRC-CLA-OFRFRC-CLA-RFRSCN-ADP-NTFSCN-CSO-INFSCN-RTR-NNRSCN-TRF-NAVVDR-CSO-ADTVDR-CSO-AKEVDR-CSO-DACVDR-CSO-DETVDR-CSO-DFRVDR-CSO-FAVVDR-CSO-MSPVDR-CSO-RESVDR-CSO-SIRVDR-TFR-KEVVDR-TFR-PCDVDR-TFR-PDDVDR-TFR-PSDVDR-TFR-PVRVDR-TFR-RMNVER-EVA-AIAVER-EVA-EFAVER-EVA-EFPVER-EVA-EIRVER-EVA-ELXVER-EVA-EPAVER-EVA-GRVVER-RPT-AVIVER-RPT-HLOVER-RPT-NIDVER-RPT-PERVER-RPT-RPDVER-RPT-VDTVER-TFR-EVUVER-TFR-IRIVER-TFR-MAVVER-TFR-MHRVER-TFR-MRHVER-TFR-NRI
Referenced by 3 KSIs
References
Change history
2026-06-24Official launch of the FedRAMP Consolidated Rules for 2026.