Federal Risk and Authorization Management Program

E308975

The Federal Risk and Authorization Management Program (FedRAMP) is a U.S. government-wide framework that standardizes security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies.

All labels observed (4)

How this entity was disambiguated

Statements (49)

Predicate Object
instanceOf U.S. federal program ⓘ
government security program ⓘ
abbreviation FedRAMP ⓘ
appliesTo U.S. federal agencies ⓘ
cloud products ⓘ
cloud services ⓘ
authorizingBodies Joint Authorization Board ⓘ
basedOnStandard FIPS 199 ⓘ
FIPS 200 ⓘ
NIST SP 800-53 ⓘ
benefit increased security consistency across agencies ⓘ
reduced duplication of security assessments ⓘ
reuse of security authorizations ⓘ
collaboratesWith Department of Homeland Security ⓘ
National Institute of Standards and Technology ⓘ
Office of Management and Budget ⓘ
country United States ⓘ
definesProcess authorization to operate ⓘ
continuous monitoring of cloud systems ⓘ
security assessment ⓘ
establishedBy U.S. Office of Management and Budget ⓘ
excludes most Department of Defense on-premises systems ⓘ
focusesOn cloud computing security ⓘ
information security ⓘ
risk management ⓘ
governingBody U.S. General Services Administration ⓘ
hasAcronym 3PAO ⓘ
hasAuthorizationType Agency Authority to Operate ⓘ
Provisional Authority to Operate ⓘ
hasWebsite https://www.fedramp.gov ⓘ
JointAuthorizationBoardMembers Department of Defense ⓘ
Department of Homeland Security ⓘ
General Services Administration ⓘ
jurisdiction U.S. federal government ⓘ
language English ⓘ
overseenBy FedRAMP Program Management Office ⓘ
policyInstrument OMB memorandum ⓘ
purpose standardize continuous monitoring for cloud services ⓘ
standardize security assessment for cloud services ⓘ
standardize security authorization for cloud services ⓘ
requires independent third-party assessment ⓘ
requiresComplianceFrom cloud service providers seeking federal customers ⓘ
scope federal civilian agencies ⓘ
sector information technology governance ⓘ
public sector ⓘ
uses Third Party Assessment Organizations ⓘ
usesConcept continuous monitoring ⓘ
risk-based categorization ⓘ
security controls baseline ⓘ

How these facts were elicited

Referenced by (19)

Full triples — surface form annotated when it differs from this entity's canonical label.

FedRAMP Program Management Office → partOf → Federal Risk and Authorization Management Program ⓘ
FedRAMP Program Management Office → usesFramework → FedRAMP Security Assessment Framework ⓘ
linked to: Federal Risk and Authorization Management Program
Amazon S3 → supportsCompliance → FedRAMP (for eligible regions and accounts) ⓘ
linked to: Federal Risk and Authorization Management Program
Federal Risk and Authorization Management Program → abbreviation → FedRAMP ⓘ
linked to: Federal Risk and Authorization Management Program
GSA → operatesProgram → FedRAMP ⓘ
linked to: Federal Risk and Authorization Management Program
FedRAMP Joint Authorization Board Provisional ATO → usedWithin → Federal Risk and Authorization Management Program ⓘ
FedRAMP Joint Authorization Board Provisional ATO → usedWithin → FedRAMP ⓘ
linked to: Federal Risk and Authorization Management Program
FedRAMP Joint Authorization Board Provisional ATO → basedOn → FedRAMP Security Assessment Framework ⓘ
linked to: Federal Risk and Authorization Management Program
3PAO → followsStandard → FedRAMP Security Assessment Framework ⓘ
linked to: Federal Risk and Authorization Management Program
Joint Authorization Board → partOf → Federal Risk and Authorization Management Program ⓘ
Third Party Assessment Organizations → usedInProgram → Federal Risk and Authorization Management Program ⓘ
FedRAMP Joint Authorization Board → parentProgram → Federal Risk and Authorization Management Program ⓘ
subject linked to: JAB
FedRAMP Agency ATO → regulatedBy → Federal Risk and Authorization Management Program ⓘ
Department of Defense representative on JAB → roleIn → Federal Risk and Authorization Management Program ⓘ
FedRAMP High impact level → partOf → Federal Risk and Authorization Management Program ⓘ
FedRAMP High impact level → governedBy → FedRAMP Security Assessment Framework ⓘ
linked to: Federal Risk and Authorization Management Program
FedRAMP Marketplace package → governingBody → Federal Risk and Authorization Management Program ⓘ
FedRAMP Low → partOf → Federal Risk and Authorization Management Program ⓘ
FedRAMP security controls → partOf → Federal Risk and Authorization Management Program ⓘ