Purpose
FedRAMP gives agencies and cloud service providers a common approach to security requirements, documentation, assessment, authorization, and ongoing monitoring.
Core work
- Define the service boundary and architecture
- Implement and document required controls
- Collect and organize evidence
- Undergo independent assessment where required
- Resolve findings and support authorization decisions
- Perform continuous monitoring and manage significant change
Authorization is not permanent
Cloud services change, threats change, vulnerabilities emerge, and control evidence ages. Continuous monitoring and change management are central to maintaining confidence.
Shared responsibility
The provider, agency customer, assessors, and authorizing officials each have responsibilities. Clear boundaries and customer-configurable responsibilities are essential.
Certification relevance
This subject appears in or supports the following certification bodies of knowledge: