惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
罗磊的独立博客
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Last Week in AI
Last Week in AI
云风的 BLOG
云风的 BLOG
T
The Blog of Author Tim Ferriss
Y
Y Combinator Blog
A
About on SuperTechFans
WordPress大学
WordPress大学
B
Blog
Martin Fowler
Martin Fowler
Jina AI
Jina AI
I
InfoQ
P
Proofpoint News Feed
小众软件
小众软件
S
SegmentFault 最新的问题
V
V2EX
B
Blog RSS Feed
量子位
大猫的无限游戏
大猫的无限游戏
aimingoo的专栏
aimingoo的专栏
博客园 - 三生石上(FineUI控件)
MongoDB | Blog
MongoDB | Blog
美团技术团队

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity Wiz + Spotify Backstage: Security at the Developer’s Desk
The Agile FedRAMP Playbook, Part 2: Proactive Risk Manage...
Annam Iyer, Kelsey Nelson, Bryan Rosensteel · 2026-02-20 · via Wiz Blog | RSS feed

The Shift from "Periodic" to "Continuous"

In the first part of our FedRAMP series, we explored Wiz’s accelerated journey to FedRAMP High. However, seasoned CSPs (Cloud Service Providers) know that obtaining the FedRAMP authorization is only the beginning. The real challenge lies in maintaining that security posture through ongoing FedRAMP Continuous Monitoring (ConMon).

Traditionally, compliance monitoring has been synonymous with "point-in-time" scanning. Organizations would run a scan, generate a report, and spend weeks manually reconciling security posture against requirements. In a FedRAMP environment, this reactive, manual approach is not sustainable amidst an evolving threat landscape.

FedRAMP Rev 5 processes necessitate a robust ConMon program built around monthly reporting, and ongoing FedRAMP reforms are pushing ConMon towards data-driven automated validation of risk, a move that directly supports the goals of Executive Order 14028 on Improving the Nation’s Cybersecurity. To meet these stringent requirements and the Executive Order’s mandates for increased visibility into cybersecurity data without paralyzing software development, organizations must move away from disparate tools and spreadsheets. Effective ConMon today demands a proactive risk management strategy built on automated visibility and deep architectural context, allowing teams to identify and remediate vulnerabilities before they can be exploited.

Visibility: You Can’t Protect What You Can’t See

The foundation of proactive risk management is a complete, automated inventory with context on how different resources connect. FedRAMP stresses the importance of having accurate inventory assessments through Rev 5’s CM-8 (Information System Component Inventory) control, requiring organizations to maintain an accurate account of all system components.  The same is true if your organization is pursuing the newer FedRAMP 20x assessment, with Key Security Indicator (KSI) PI-00 requiring an up-to-date asset inventory or code defining all deployed assets.

Figure 1: Wiz for Gov helps not only quickly helps build SBOMs, but to provide quick, accessible visibility into many different technologies deployed, assisting to meet the intent behind many NIST SP 800-53r5 based FedRAMP Rev 5 controls as well as the newer FedRAMP 20x KSIs

In a dynamic cloud environment, manual spreadsheets are obsolete from almost the moment they are generated. Wiz for U.S. Government (Wiz for Gov) provides an agentless, accurate view of cloud environments within minutes. This isn't just a list of virtual machines; it’s a deep map of:

  • Identities (Who has access?)

  • Workloads (What is running?)

  • Data (Where is the sensitive information?)

  • Network (How is it exposed?)

Figure 2: Automating discovery and identification of what is running, who has access, where sensitive information resides, and how these resources are exposed are critical in reducing the effort required to meet monthly FedRAMP ConMon requirements

Prioritization: Beyond the CVE

The "noise" of traditional vulnerability management is the antagonist of agility. A standard vulnerability scan might return 10,000 "High" or "Critical" Common Vulnerabilities and Exposures (CVEs) based upon the Common Vulnerability Scoring System (CVSS). For a FedRAMP environment, the Plan of Action and Milestones (POA&M) process requires you to track and remediate these within strict timelines (30 days for CVEs with a High CVSS score). Without upfront risk adjustment, this requirement can quickly become burdensome.

Helpfully, NIST SP 800-53r5, the primary basis for the FedRAMP baseline controls in Rev 5 assessments, does not view vulnerability severity as synonymous with risk.  Instead, risk is defined as “[a] measure of the extent to which an entity is threatened by a potential circumstance or event, and typically is a function of: (i) the adverse impact, or magnitude of harm, that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.”

This definition underscores that, without the context of impact and potential of occurrence, it is not possible to understand the impact on risk reduction by focusing solely on the CVSS score of a CVE.  If you treat every CVE as equal, your engineering team will spend the majority of their time on maintenance at the expense of innovation.

New initiatives around FedRAMP, including the 20x program, double down on this broader view of risk through POA&M risk adjustment, explicitly moving away from simple vulnerability reporting to a more prioritized approach to risk remediation and mitigation.  Wiz for Gov provides accelerated access to details necessary for these risk adjustments through the Wiz Security Graph, effectively automating the evidentiary burden for Information System Security Officers who must justify POA&M remediation timelines to their Authorizing Officials. Instead of a flat list, Wiz identifies "Toxic Combinations." For example:

  • Low Risk: A High-severity CVE on an internal, isolated server. (Low Likelihood, Low impact)

  • Critical Risk: The same High-severity CVE on a server that is publicly exposed and has a high-privileged identity attached to it. (High Likelihood, High impact)

By prioritizing remediation based on the NIST 800-53r5 definition of risk, organizations can implement FedRAMP Rev5's RA-5 (Vulnerability Monitoring) and RA-07 (Risk Response) controls, managing vulnerabilities in accordance with their risk tolerance and focusing on the top issues that actually represent a path for an attacker.

Figure 3: With thousands of preconfigured rules out of the box and the ability to custom define, Wiz for Gov quickly automates risk discovery and assessment, providing prioritized findings based upon identified toxic combinations that pose the greatest risk to organizations

The newer FedRAMP 20x framework expands upon this methodology for prioritizing risk remediation based upon impact through KSIs such as SC-06 and MLA-05 which call for risk-informed, prioritized approaches for security patching and vulnerability remediation.

Automating the ConMon Cycle

Continuous monitoring isn't just about finding risks; it’s about the "Agile Foundation" previously discussed in Lesson Three of Part 1. Wiz for Gov helps automate the evidence collection needed for monthly ConMon reports. This table highlights several of these FedRAMP controls.

FedRAMP Rev 5 RequirementWiz for Gov Capability
Configuration Settings (CM-6)Continuous assessment against CIS benchmarks and FedRAMP-specific configuration baselines
Information System Component Inventory (CM-8)Automated, real-time discovery of all cloud resources and technologies
Vulnerability Scanning (RA-5)Agentless scanning of operating systems, applications, and libraries without performance impact
Risk Response(RA-7)Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance
Protection of Information at Rest (SC-28)Discovery and protection of sensitive data to protect against unauthorized disclosure

Turning "Audit Time" into "Uptime"

By using Wiz for Gov to handle the heavy lifting of proactive risk management, Wiz has been able to significantly reduce the administrative burden of our own FedRAMP High ConMon. This automation allows our security team to act as partners to our developers, providing them with clear, prioritized instructions rather than "walls of red" in a spreadsheet.

In the next part of this series, we will look at Preventative Risk Management, and how we "shift left" to build securely by design within the software development lifecycle to stop these risks from reaching production in the first place.