FedRAMP Low

E1023369

FedRAMP Low is a baseline security authorization level within the U.S. Federal Risk and Authorization Management Program designed for cloud systems handling the least sensitive federal information and requiring minimal security controls.

All labels observed (3)

Label Occurrences
FedRAMP Low baseline 2
FedRAMP Low canonical 1
FedRAMP Low impact level 1

How this entity was disambiguated

Statements (49)

Predicate Object
instanceOf FedRAMP security baseline ⓘ
information security standard ⓘ
appliesTo cloud service offerings ⓘ
federal information systems ⓘ
assessmentPerformedBy Third Party Assessment Organization ⓘ
authorizationBoundary applies to systems categorized as low impact under FIPS 199 ⓘ
authorizationType security authorization baseline ⓘ
basedOnStandard FIPS 199 ⓘ
NIST SP 800-53 ⓘ
controlFamilyCoverage access control ⓘ
audit and accountability ⓘ
configuration management ⓘ
contingency planning ⓘ
identification and authentication ⓘ
incident response ⓘ
maintenance ⓘ
media protection ⓘ
physical and environmental protection ⓘ
risk assessment ⓘ
system and communications protection ⓘ
system and information integrity ⓘ
countryOfOrigin United States ⓘ
documentationRequirement Plan of Action and Milestones ⓘ
Security Assessment Plan ⓘ
Security Assessment Report ⓘ
System Security Plan ⓘ
governingBody FedRAMP Program Management Office ⓘ
impactCategory availability low ⓘ
confidentiality low ⓘ
integrity low ⓘ
includes management security controls ⓘ
operational security controls ⓘ
technical security controls ⓘ
informationSensitivity least sensitive federal information ⓘ
objective to ensure adequate security for low-impact federal cloud services ⓘ
overseenBy Joint Authorization Board ⓘ
U.S. General Services Administration ⓘ
partOf Federal Risk and Authorization Management Program ⓘ
purpose to define minimum security requirements for low-impact federal cloud systems ⓘ
relatedBaseline FedRAMP High ⓘ
FedRAMP Moderate ⓘ
requires minimal security controls compared to FedRAMP Moderate and High ⓘ
riskLevel low impact to individuals ⓘ
low impact to organizational assets ⓘ
low impact to organizational operations ⓘ
securityImpactLevel low ⓘ
usedBy U.S. federal agencies ⓘ
cloud service providers seeking FedRAMP authorization ⓘ
usesControlBaselineFrom NIST SP 800-53 low baseline ⓘ
linked to: NIST SP 800-53

How these facts were elicited

Referenced by (4)

Full triples — surface form annotated when it differs from this entity's canonical label.

FedRAMP Moderate → relatedStandard → FedRAMP Low ⓘ
FedRAMP High impact level → hasHigherStringencyThan → FedRAMP Low impact level ⓘ
linked to: FedRAMP Low
FedRAMP High impact level → hasStricterControlsThan → FedRAMP Low baseline ⓘ
linked to: FedRAMP Low
FedRAMP security controls → hasComponent → FedRAMP Low baseline ⓘ
linked to: FedRAMP Low