Menu
Home Explore People Places Arts History Plants & Animals Science Life & Culture Technology
On this page
FedRAMP
US government cybersecurity program

The Federal Risk and Authorization Management Program (FedRAMP) is a United States federal government-wide compliance program that standardizes security assessment, authorization, and continuous monitoring for cloud services. Established by the Office of Management and Budget in 2011, FedRAMP aims to provide a cost-effective, risk-based approach for federal cloud service adoption. The General Services Administration manages its program office, ensuring cloud providers meet required security standards. Authorization can be granted via the Joint Authorization Board or through individual agencies. FedRAMP accredits cloud models including IaaS, PaaS, and SaaS, replacing earlier agency-specific assessments under the Federal Information Security Management Act.

Related Image Collections Add Image
We don't have any YouTube videos related to FedRAMP yet.
We don't have any PDF documents related to FedRAMP yet.
We don't have any Books related to FedRAMP yet.
We don't have any archived web articles related to FedRAMP yet.

Governance and applicable laws

FedRAMP is governed by different Executive Branch entities that collaborate to develop, manage, and operate the program.8 These entities include:

There are several laws, mandates, and policies that are foundational to FedRAMP. FISMA–the Federal Information Security Modernization Act–requires that agencies authorize the information systems that they use. FedRAMP is FISMA for the cloud. The FedRAMP Policy Memo requires federal agencies to use FedRAMP when assessing, authorizing, and continuously monitoring cloud services in order to aid agencies in the authorization process as well as save government resources and eliminate duplicative efforts.9 FedRAMP's security baselines are derived from NIST SP 800-53 (as revised) with a set of control enhancements that pertain to the unique security requirements of cloud computing.

Third-party assessment organizations

Third-party assessment organizations (3PAOs) play a critical role in the FedRAMP security assessment process, as they are the independent assessment organizations that verify cloud providers’ security implementations and provide the overall risk posture of a cloud environment for a security authorization decision.10 Accredited by the American Association for Laboratory Accreditation (A2LA), these assessment organizations must demonstrate independence and the technical competence required to test security implementations and collect representative evidence.

FedRAMP Marketplace

The FedRAMP Marketplace provides a searchable, sortable database of Cloud Service Offerings (CSOs) that have achieved a FedRAMP designation.11 3PAOs, accredited auditors that can perform the FedRAMP assessment, are listed within the Marketplace. The FedRAMP Marketplace is maintained by the FedRAMP Program Management Office (PMO).12

See also

References

  1. "FedRAMP.gov". FedRAMP.gov. 2020-03-26. Retrieved 2020-04-05. https://fedramp.gov/

  2. "Policy memo" (PDF). www.fedramp.gov. Retrieved 2020-04-05. https://www.fedramp.gov/assets/resources/documents/FedRAMP_Policy_Memo.pdf

  3. "FedRAMP.gov". FedRAMP.gov. 2020-03-26. Retrieved 2020-04-05. https://fedramp.gov/

  4. "Policy memo" (PDF). www.fedramp.gov. Retrieved 2020-04-05. https://www.fedramp.gov/assets/resources/documents/FedRAMP_Policy_Memo.pdf

  5. "Get Authorized: Joint Authorization Board". FedRAMP.gov. Retrieved 2020-04-05. https://fedramp.gov/jab-authorization/

  6. "Get Authorized: Agency Authorization". FedRAMP.gov. Retrieved 2020-04-05. https://fedramp.gov/agency-authorization/

  7. "DOD turns to FedRAMP and cloud brokering -- FCW". FCW. 2014-05-21. Archived from the original on 2020-10-31. Retrieved 2020-04-05. https://web.archive.org/web/20201031105521/https://fcw.com/articles/2014/05/21/drill-down-dod-fedramp-and-cloud-brokering.aspx

  8. "Governance". FedRAMP.gov. Retrieved 2020-04-05. https://fedramp.gov/governance/

  9. "Policy memo" (PDF). www.fedramp.gov. Retrieved 2020-04-05. https://www.fedramp.gov/assets/resources/documents/FedRAMP_Policy_Memo.pdf

  10. "Policy memo" (PDF). www.fedramp.gov. Retrieved 2020-04-05. https://www.fedramp.gov/assets/resources/documents/FedRAMP_Policy_Memo.pdf

  11. "The Federal Risk And Management Program Dashboard". marketplace.fedramp.gov. Retrieved 2021-07-28. https://marketplace.fedramp.gov/

  12. "Marketplace designations" (PDF). www.fedramp.gov. Retrieved 2020-04-05. https://www.fedramp.gov/assets/resources/documents/FedRAMP_Marketplace_Designations_for_Cloud_Service_Providers.pdf