FedRAMP
What is FedRAMP?
The Federal Risk and Authorization Management Program, a US government programme that standardises security assessment and authorisation for cloud services used by federal agencies.
Related terms
Frameworks that govern fedramp
What the standards actually require on fedramp
Requirements naming fedramp across 6 standards, quoted from the control text.
FedRAMP defines four baselines based on FIPS 199 system impact level: (a) LI-SAAS (Low Impact SaaS) - low-impact SaaS with no sensitive data + 156 controls + accelerated authorization path; (b) LOW (Low Impact) - 156 controls;
FedRAMP-Baselines · FedRAMP Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters →Section 9.4 of IRS Publication 1075 establishes specific requirements for cloud services and addresses the prohibition on offshore processing of FTI.
IRSPub1075-Section94-Cloud-FedRAMP-Offshore-Prohibition-CSP-USRegion-PrivateGovCloud-AzureGov-AWSGov · IRS Pub 1075 Section 9.4 + Cloud Services + FedRAMP Authorisation Required + Offshore Prohibition + AWS GovCloud + Azure Government + Oracle US Federal + Google Workspace Federal + US-Region Data Residency →FISMA + FedRAMP coordination for cloud services. FEDRAMP (Federal Risk and Authorization Management Program) operationalizes FISMA for CLOUD SERVICES used by federal agencies (established by OMB Memorandum M-11-30 + modernized by M-24-15 of July 2024).
FISMA-FedRAMP-Cloud-Coordination · FedRAMP for Cloud Services + 800-37 ATO Integration →Coordinate MARS-E compliance with adjacent federal programmes and audit regimes. IRS Publication 1075 (Safeguarding Federal Tax Information) compliance for Federal Tax Information (FTI) processing under IRC Section 6103 + Safeguard Procedures Report (SPR) ever...
MARS-E-Cross-Program-Coordination-IRS-Pub-1075-FedRAMP-CMS-ARS-HHS-OIG-Joint-Audit-3PAO · MARS-E Cross-Program + IRS Pub 1075 + FedRAMP + CMS ARS + HHS OIG + Joint Audit + 3PAO →ISMAP Assessment positions ISMAP within the comprehensive Japanese and international cloud security regulatory landscape. (1) External Assessment by ISMAP-Approved Auditor: CSP must undergo annual third-party assessment by ISMAP-approved audit organisation inc...
ISMAP-Assessment-ExternalAuditor-AnnualReview-CustomerTransparency-Coord-FedRAMP-IRAP-GCloud-PIPA-ISO27017 · ISMAP Assessment - External ISMAP-Approved Auditor + Annual Review + Customer Information and Transparency + Coordination FedRAMP/UK G-Cloud/Australia IRAP/Singapore MTCS + ISO 27017 + PIPA + Japan Digital Agency →Detect network services not authorized; audit or alert FedRAMP-defined personnel.
SI-4(22) · Unauthorized Network Services →Questions people ask about fedramp
What is FedRAMP?
Why is FedRAMP important for compliance?
What concepts are related to FedRAMP?
Which compliance frameworks address FedRAMP?
Where can I learn more about FedRAMP?
See how FedRAMP applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.