Federal Risk and Authorization Management Program

E308975

The Federal Risk and Authorization Management Program (FedRAMP) is a U.S. government-wide framework that standardizes security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies.

All labels observed (4)

How this entity was disambiguated

Statements (49)

Predicate Object
instanceOf U.S. federal program
government security program
abbreviation FedRAMP
appliesTo U.S. federal agencies
cloud products
cloud services
authorizingBodies Joint Authorization Board
basedOnStandard FIPS 199
FIPS 200
NIST SP 800-53
benefit increased security consistency across agencies
reduced duplication of security assessments
reuse of security authorizations
collaboratesWith Department of Homeland Security
National Institute of Standards and Technology
Office of Management and Budget
country United States
definesProcess authorization to operate
continuous monitoring of cloud systems
security assessment
establishedBy U.S. Office of Management and Budget
excludes most Department of Defense on-premises systems
focusesOn cloud computing security
information security
risk management
governingBody U.S. General Services Administration
hasAcronym 3PAO
hasAuthorizationType Agency Authority to Operate
Provisional Authority to Operate
hasWebsite https://www.fedramp.gov
JointAuthorizationBoardMembers Department of Defense
Department of Homeland Security
General Services Administration
jurisdiction U.S. federal government
language English
overseenBy FedRAMP Program Management Office
policyInstrument OMB memorandum
purpose standardize continuous monitoring for cloud services
standardize security assessment for cloud services
standardize security authorization for cloud services
requires independent third-party assessment
requiresComplianceFrom cloud service providers seeking federal customers
scope federal civilian agencies
sector information technology governance
public sector
uses Third Party Assessment Organizations
usesConcept continuous monitoring
risk-based categorization
security controls baseline

How these facts were elicited

Referenced by (8)

Full triples — surface form annotated when it differs from this entity's canonical label.

FedRAMP Program Management Office partOf Federal Risk and Authorization Management Program
FedRAMP Program Management Office usesFramework FedRAMP Security Assessment Framework
linked to: Federal Risk and Authorization Management Program
Amazon S3 supportsCompliance FedRAMP (for eligible regions and accounts)
linked to: Federal Risk and Authorization Management Program
Federal Risk and Authorization Management Program abbreviation FedRAMP
linked to: Federal Risk and Authorization Management Program
GSA operatesProgram FedRAMP
linked to: Federal Risk and Authorization Management Program
FedRAMP Joint Authorization Board Provisional ATO usedWithin Federal Risk and Authorization Management Program
FedRAMP Joint Authorization Board Provisional ATO usedWithin FedRAMP
linked to: Federal Risk and Authorization Management Program
FedRAMP Joint Authorization Board Provisional ATO basedOn FedRAMP Security Assessment Framework
linked to: Federal Risk and Authorization Management Program