FedRAMP security controls

E1023779

FedRAMP security controls are a standardized set of baseline security requirements that U.S. federal agencies use to assess and authorize cloud service providers for handling government data.

All labels observed (8)

How this entity was disambiguated

Statements (48)

Predicate Object
instanceOf U.S. federal government standard ⓘ
information security requirement set ⓘ
security control baseline ⓘ
administeredBy FedRAMP Program Management Office ⓘ
alignedWith Federal Information Security Modernization Act ⓘ
NIST Risk Management Framework ⓘ
appliesTo Infrastructure as a Service offerings for federal agencies ⓘ
Platform as a Service offerings for federal agencies ⓘ
Software as a Service offerings for federal agencies ⓘ
cloud service providers ⓘ
basedOn NIST SP 800-53 security controls ⓘ
linked to: NIST SP 800-53
evaluationMethod security assessment by Third Party Assessment Organizations ⓘ
governs federal information in cloud computing environments ⓘ
hasComponent FedRAMP High baseline ⓘ
FedRAMP Low baseline ⓘ
linked to: FedRAMP Low

FedRAMP Moderate baseline ⓘ
linked to: FedRAMP Moderate
includes access control requirements ⓘ
audit and accountability requirements ⓘ
configuration management requirements ⓘ
contingency planning requirements ⓘ
incident response requirements ⓘ
management security controls ⓘ
operational security controls ⓘ
risk assessment requirements ⓘ
security assessment and authorization requirements ⓘ
system and communications protection requirements ⓘ
system and information integrity requirements ⓘ
technical security controls ⓘ
jurisdiction United States federal government ⓘ
objective ensure consistent security posture across federal cloud services ⓘ
standardize security assessment of cloud services ⓘ
partOf Federal Risk and Authorization Management Program ⓘ
purpose assess cloud service provider security ⓘ
protect U.S. government data in cloud environments ⓘ
support authorization of cloud services for federal use ⓘ
requires continuous monitoring of cloud systems ⓘ
documented security policies and procedures ⓘ
independent security assessment ⓘ
system security plan documentation ⓘ
scope availability of federal information in the cloud ⓘ
confidentiality of federal information in the cloud ⓘ
integrity of federal information in the cloud ⓘ
targetData federal information categorized as High impact ⓘ
federal information categorized as Low impact ⓘ
federal information categorized as Moderate impact ⓘ
usedBy U.S. federal agencies ⓘ
usedFor FedRAMP Authorization to Operate ⓘ
linked to: FedRAMP Agency ATO

FedRAMP Provisional Authorization to Operate ⓘ

How these facts were elicited

Referenced by (10)

Full triples — surface form annotated when it differs from this entity's canonical label.

NIST SP 800-53 → mappingAvailableTo → FedRAMP security controls ⓘ
Joint Authorization Board → usesFramework → FedRAMP security baselines ⓘ
linked to: FedRAMP security controls
Third Party Assessment Organizations → assessmentBasis → FedRAMP security baselines ⓘ
linked to: FedRAMP security controls
FedRAMP Agency ATO → constrainedBy → FedRAMP baseline controls ⓘ
linked to: FedRAMP security controls
FedRAMP High impact level → hasControlBaseline → FedRAMP High security control baseline ⓘ
linked to: FedRAMP security controls
FedRAMP High impact level → governedBy → FedRAMP High Baseline Requirements ⓘ
linked to: FedRAMP security controls
FedRAMP High impact level → governedBy → FedRAMP High Security Controls Baseline document ⓘ
linked to: FedRAMP security controls
FedRAMP Marketplace package → conformsTo → FedRAMP documentation standards ⓘ
linked to: FedRAMP security controls
FedRAMP Marketplace package → relatedTo → FedRAMP security assessment framework ⓘ
linked to: FedRAMP security controls