FedRAMP High impact level

E1023367

FedRAMP High impact level is the most stringent FedRAMP security categorization, applied to cloud systems whose compromise could severely affect an agency’s operations, assets, or individuals.

All labels observed (3)

How this entity was disambiguated

Statements (48)

Predicate Object
instanceOf FedRAMP impact level ⓘ
information security categorization ⓘ
alignedWith NIST Risk Management Framework ⓘ
appliesTo Infrastructure-as-a-Service offerings ⓘ
Platform-as-a-Service offerings ⓘ
Software-as-a-Service offerings ⓘ
cloud information systems ⓘ
federal information systems hosted in the cloud ⓘ
associatedWith severe adverse effect on individuals ⓘ
severe adverse effect on organizational assets ⓘ
severe adverse effect on organizational operations ⓘ
basedOn FIPS 199 security categorization ⓘ
NIST SP 800-60 ⓘ
definedBy FedRAMP Program Management Office ⓘ
governedBy FedRAMP High Baseline Requirements ⓘ
FedRAMP High Security Controls Baseline document ⓘ
FedRAMP Security Assessment Framework ⓘ
hasControlBaseline FedRAMP High security control baseline ⓘ
hasHigherStringencyThan FedRAMP Low impact level ⓘ
linked to: FedRAMP Low

FedRAMP Moderate impact level ⓘ
hasImpactLevel High ⓘ
hasPurpose to protect highly sensitive federal information in cloud environments ⓘ
hasRiskCategory High ⓘ
hasStricterControlsThan FedRAMP Low baseline ⓘ
linked to: FedRAMP Low

FedRAMP Moderate baseline ⓘ
linked to: FedRAMP Moderate
partOf FedRAMP ⓘ
Federal Risk and Authorization Management Program ⓘ
requires authorization by a federal agency or the Joint Authorization Board ⓘ
configuration management controls ⓘ
continuous monitoring ⓘ
documented security policies and procedures ⓘ
encryption of data at rest ⓘ
encryption of data in transit ⓘ
enhanced availability protections ⓘ
enhanced confidentiality protections ⓘ
enhanced integrity protections ⓘ
formal risk assessments ⓘ
incident response capabilities ⓘ
independent third-party assessment ⓘ
multi-factor authentication ⓘ
strong access control measures ⓘ
vulnerability scanning ⓘ
usedBy U.S. federal agencies ⓘ
usedFor systems where loss of availability could have severe or catastrophic adverse effect ⓘ
systems where loss of confidentiality could have severe or catastrophic adverse effect ⓘ
systems where loss of integrity could have severe or catastrophic adverse effect ⓘ
usedInContextOf U.S. federal cloud authorizations ⓘ
usesControlBaselineFrom NIST SP 800-53 ⓘ

How these facts were elicited

Referenced by (5)

Full triples — surface form annotated when it differs from this entity's canonical label.

FedRAMP Moderate → relatedStandard → FedRAMP High ⓘ
linked to: FedRAMP High impact level
Azure Government → compliesWith → FedRAMP High ⓘ
linked to: FedRAMP High impact level
FedRAMP Low → relatedBaseline → FedRAMP High ⓘ
linked to: FedRAMP High impact level
FedRAMP security controls → hasComponent → FedRAMP High baseline ⓘ
linked to: FedRAMP High impact level