Skip to content

docs(federal): document PAIN-keyed FedRAMP VDR remediation deadlines - #15719

Merged
Maffooch merged 1 commit into
devfrom
docs/fedramp-pain-matrix
Aug 19, 2026
Merged

docs(federal): document PAIN-keyed FedRAMP VDR remediation deadlines#15719
Maffooch merged 1 commit into
devfrom
docs/fedramp-pain-matrix

Conversation

@devGregA

Copy link
Copy Markdown
Contributor

Description

Documents a Potential Agency Impact (PAIN) dimension on the FedRAMP VDR remediation deadlines. Pairs with a Pro change; this is the user-facing half.

The three shipped VDR tiers give every credibly exploitable, internet-reachable finding the same deadline whatever the damage its exploitation would do. FedRAMP's published table crosses those same conditions with a PAIN N-rating, and the spread across ratings is large — from 2 days to 48 in the tightest column. This documents the full twelve-cell table and how to switch to it.

Each rating is labelled with FedRAMP's own customer-effect wording rather than a bare number, because "N4" tells a compliance owner nothing about the judgment being asked of them.

It also records the three behaviours somebody enabling this needs to be able to predict:

  • An unrated finding keeps its base deadline, so nothing is re-dated at the moment the setting is switched on — deadlines tighten as findings get rated.
  • N1 has no row, because FedRAMP's table starts at N2. DefectDojo does not invent a row FedRAMP has not published.
  • Enabling the table replaces the three tiers rather than combining with them, so a finding rated N2 gets the N2 deadline rather than the tier it would have had unrated.

Plus a note that PAIN is deliberately a person's judgment: FedRAMP asks the provider to estimate the effect on agencies using the service and explicitly declines to prescribe a method, so a rule can propose a rating and route it for review, but the confirmation is the provider's to defend.

While in the same section, documents the existing Use Asset Exposure for VDR Tiering option, which was already configurable and undocumented.

English only, consistent with how this page's translated variants are handled.

Documentation only; no code or behaviour change in this repository.

Pairs with the dojo-pro change adding a Potential Agency Impact dimension to the VDR
tiers. Documents the twelve-cell table with FedRAMP's own customer-effect wording on each
rating, since "N4" says nothing about the judgment a compliance owner is being asked to
make.

Leads with the reason the dimension exists: the three shipped tiers give every
exploitable, internet-reachable finding the same deadline whatever exploitation would
actually do, and FedRAMP's table does not.

Also records the three behaviours somebody enabling this needs to predict: an unrated
finding keeps its base deadline (so nothing is re-dated at the moment you switch it on),
N1 has no row because FedRAMP publishes none, and enabling the table replaces the three
tiers rather than combining with them.

Adds the exposure-verdict option to the existing VDR section while nearby -- it was
already configurable and undocumented.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@devGregA
devGregA requested a review from Maffooch as a code owner August 19, 2026 02:05
@devGregA devGregA added this to the 3.3.0 milestone Aug 19, 2026
@devGregA
devGregA requested a review from blakeaowens as a code owner August 19, 2026 02:05
@github-actions github-actions Bot added the docs label Aug 19, 2026
@Maffooch
Maffooch merged commit 806b634 into dev Aug 19, 2026
23 checks passed
@Maffooch
Maffooch deleted the docs/fedramp-pain-matrix branch August 19, 2026 23:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants