Skip to content
Menu
Cloud Gal 42
  • Home
Cloud Gal 42

QuickGuide: FedRAMP

February 8, 2021May 13, 2021 by admin

The Federal Risk and Authorization Management Program (FedRAMP) is a U.S. government–wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. It is the result of close collaboration with cybersecurity and cloud experts from GSA, NIST, DHS, DOD, NSA, OMB, the Federal CIO Council and its working groups, and private industry.

FedRAMP goals include:

  • Accelerate the adoption of secure cloud solutions through reuse of assessments and authorizations
  • Increase confidence in security of cloud solutions
  • Achieve consistent security authorizations using a baseline set of agreed-upon standards to be used for cloud product approval in or outside of FedRAMP
  • Ensure consistent application of existing security practices
  • Increase confidence in security assessments
  • Increase automation and near-real-time data for continuous monitoring

FedRAMP enables the reuse of existing security assessments across the U.S. government while simultaneously providing improved real-time security visibility. Central to this strategy is the FedRAMP Joint Authorization Board (JAB), which was tasked with

reviewing security assessment packages based on a prioritized approach. The JAB can also grant provisional CSP authorization that all federal agencies can leverage when granting an agency authority to operate, which saves both time and money.

Another FedRAMP innovation was the establishment of Third-Party Assessment Organizations (3PAOs), which were authorized by the federal government to independently verify and validate the implementation of security controls within a CSP environment.

The JAB established the criteria necessary to qualify as a 3PAO. Certifying criteria includes independence and quality management specifications based on ISO/IEC standards to ensure the requisite independence and quality systems needed to assess the security control implementations by CSPs. Technical competency criteria were also set based on an evaluation of knowledge of security authorizations to ensure the requisite skills and expertise to conduct such assessments.

The FedRAMP assessment process is initiated by agencies or cloud service providers by starting a security authorization using the FedRAMP requirements, which are FISMA compliant and based on the NIST 800-53r4, and initiating work with the FedRAMP PMO. CSPs must implement the FedRAMP security requirements on their environment and hire a FedRAMP-approved 3PAO to perform an independent assessment to audit the cloud system and provide a security assessment package for review.

Related

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Role of AI/ML in Cybersecurity
  • QuickGuide: Security on OCI
  • The Cloud Management Plane
  • Secure Installation and Configuration of Virtualized Cloud Datacenters
  • Cloud Datacenter: Hardware-specific Security Configuration Requirements

Recent Comments

  • Rafael on Installing Debian on OCI
  • Jorge on Installing Debian on OCI
  • admin on Installing Debian on OCI
  • Andreas on Installing Debian on OCI
  • admin on Installing Debian on OCI

Archives

  • December 2022
  • February 2022
  • September 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • February 2021
  • January 2021
  • November 2020
  • October 2020

Categories

  • aws
  • bcdr
  • cloud
  • cloudsecurity
  • compliance
  • informationsecurity
  • oracle
  • pci
  • QuickGuide
  • security
©2025 Cloud Gal 42 | Powered by WordPress and Superb Themes!