Federal Risk and Authorization Management Program compliance for cloud services
FedRAMP (Federal Risk and Authorization Management Program) provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies.
FedRAMP Overview
Impact Levels
Level
Data Sensitivity
Examples
Controls
Low
Limited adverse effect
Public websites
125 controls
Moderate
Serious adverse effect
PII, business sensitive
325 controls
High
Severe/catastrophic effect
Law enforcement, healthcare
421 controls
Authorization Paths
┌─────────────────────────────────────────────────────────────────────────────┐
│ FEDRAMP AUTHORIZATION PATHS │
└─────────────────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────┐ ┌─────────────────────────────────┐
│ JAB Authorization │ │ Agency Authorization │
│ │ │ │
│ Joint Authorization Board │ │ Single agency sponsor │
│ Provisional ATO (P-ATO) │ │ Agency-specific ATO │
│ Reusable across agencies │ │ Can leverage for other agencies│
│ Higher rigor, longer timeline │ │ Faster, agency-specific │
└─────────────────────────────────┘ └─────────────────────────────────┘
This section fulfills ISO 13485 requirements for regulatory requirements (4.1.1) and documentation control (4.2.4), and ISO 27001 requirements for information security policies (A.5.1), access control (A.5.15), incident management (A.5.24), and compliance with legal requirements (A.5.31).