FedRAMP Rev 5
FedRAMP: Coordination with FISMA, NIST RMF, NIST 800-53 Rev 5 and Status

FedRAMP Rev 5 FedRAMP-NIST-800-53-Rev5: Coordination with NIST SP 800-53 Rev 5 + FedRAMP High + FedRAMP Moderate frameworks

FedRAMP Rev 5 is operationalised against NIST SP 800-53 Revision 5 (published September 2020) which contains 1,189 controls + control enhancements across 20 families (AC + AT + AU + CA + CM + CP + IA + IR + MA + MP + PE + PL + PM + PS + PT + RA + SA + SC + SI + SR). FedRAMP-SPECIFIC OVERLAY PARAMETERS in the FedRAMP Rev 5 Baselines mandate specific values for selected parameters (e.g. password length minimum + cryptographic algorithm strength + audit retention period + access review frequency). The FedRAMP MODERATE BASELINE (323 controls verified in the graph as 'FedRAMP Moderate' framework) covers most federal cloud workloads + the FedRAMP HIGH BASELINE (417 controls verified in the graph as 'FedRAMP High' framework) covers mission-critical workloads. The substantive control content is in those baseline-specific frameworks; this Program-level reference covers the authorization process + ConMon + 3PAO + Marketplace + M-24-15 modernization. NIST 800-53 Rev 6 is anticipated 2026-2027 + FedRAMP will evolve to Rev 6 over the subsequent 12-24 months.

Maintained by Gerard BlokdykControl text last updated

Other controls in FedRAMP: Coordination with FISMA, NIST RMF, NIST 800-53 Rev 5 and Status

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.