Term · 14. International Standards
FedRAMP (Federal Risk and Authorization Management Program) FedRAMP
Definition
US government program standardising security assessment and authorization of cloud services used by federal agencies. Three impact levels: Low, Moderate, High — mapping to FIPS 199 categorisation. Built on NIST SP 800-53 control baseline. Cloud Service Providers (CSPs) achieve Authority to Operate (ATO) via Joint Authorization Board (JAB) Provisional Authorization (P-ATO) or sponsoring agency authorization.
- Synonyms
-
- FedRAMP Moderate
- FedRAMP High
- P-ATO
- Application
- Mandatory for CSPs serving US federal agencies. IDM/IAM impact: MFA for all privileged access (PIV/CAC tokens), audit logging per NIST SP 800-92, identity lifecycle aligned to NIST SP 800-63 (IAL/AAL/FAL levels), continuous monitoring (ConMon) of identity controls.
- Standards & regulations
-
- NIST SP 800-171 Rev. 3 «Federal Risk and Authorization Management Program (FedRAMP) – A government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud»
- Sources
-
- FedRAMP — official portal primary source
Related terms
-
CMMC (Cybersecurity Maturity Model Certification) (CMMC)
US Department of Defense framework certifying cybersecurity practices of Defense Industrial Base (DIB) contractors handl …
-
CSA CCoP (Cybersecurity Code of Practice for CII, Singapore) (CSA CCoP)
Singapore Cyber Security Agency's mandatory Code of Practice for Critical Information Infrastructure (CII) operators acr …
-
ENISA (European Union Agency for Cybersecurity) (ENISA)
EU agency providing cybersecurity guidance, threat intelligence, and certification schemes across member states. Coordin …
-
EU CRA (Cyber Resilience Act) (CRA)
EU regulation (Regulation (EU) 2024/2847; in force 10 Dec 2024) imposing cybersecurity requirements on products with dig …
-
MAS TRM (Monetary Authority of Singapore — Technology Risk Management Guidelines) (MAS TRM)
Singapore central bank's prescriptive guidelines (revised 2021) for technology risk management at financial institutions …
-
SOC 2 (System and Organization Controls 2) (SOC 2)
AICPA auditing framework for service organizations, evaluating controls relevant to five Trust Services Criteria: Securi …