The FedRAMP AUTHORIZATION BOUNDARY is the precise definition of the cloud system + all of its components subject to FedRAMP authorization. Documentation requirements: (a) SYSTEM SECURITY PLAN (SSP) - documents the cloud system + boundary + control implementation per NIST 800-53 Rev 5 baseline; (b) SECURITY ASSESSMENT REPORT (SAR) - prepared by an accredited 3PAO documenting the results of the security assessment; (c) PLAN OF ACTION AND MILESTONES (POA&M) - tracks open weaknesses + remediation plans + milestones; (d) BOUNDARY DIAGRAM with data-flow diagrams + asset inventory + interconnection inventory; (e) CONTINUOUS MONITORING PLAN (ConMon Plan); (f) INCIDENT RESPONSE PLAN (IRP); (g) CONFIGURATION MANAGEMENT PLAN (CMP); (h) CONTINGENCY PLAN; (i) PRIVACY IMPACT ASSESSMENT (PIA); (j) eAUTHENTICATION RISK ASSESSMENT; (k) others per FedRAMP PMO templates. The SSP is the central authorization-package artefact + must be kept current through the authorization lifecycle + reviewed during ConMon.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.