Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, individual lessons, and BMC Cyber Challenge activities.

Government programAdvanced

FedRAMP

FedRAMP establishes security requirements and repeatable authorization processes for cloud services used by United States federal agencies.

Purpose

FedRAMP gives agencies and cloud service providers a common approach to security requirements, documentation, assessment, authorization, and ongoing monitoring.

Core work

  • Define the service boundary and architecture
  • Implement and document required controls
  • Collect and organize evidence
  • Undergo independent assessment where required
  • Resolve findings and support authorization decisions
  • Perform continuous monitoring and manage significant change

Authorization is not permanent

Cloud services change, threats change, vulnerabilities emerge, and control evidence ages. Continuous monitoring and change management are central to maintaining confidence.

Shared responsibility

The provider, agency customer, assessors, and authorizing officials each have responsibilities. Clear boundaries and customer-configurable responsibilities are essential.

Certification relevance

This subject appears in or supports the following certification bodies of knowledge:

ISC2 CGRCGIAC GCCC

Authoritative sources