The organization requires the developer of the information system, system component, or information system service to produce a plan for the continuous monitoring of security control effectiveness that contains [FedRAMP Assignment: at least the minimum requirement as defined in control CA-7].
SA-4 (8) Additional FedRAMP Requirements and Guidance:
Guidance: CSP must use the same security standards regardless of where the system component or information system service is acquired.