FedRAMP Rev 5
FedRAMP: Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters

FedRAMP Rev 5 FedRAMP-PII-Privacy: FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act)

FedRAMP Rev 5 PII handling + privacy controls operationalise: (a) the PRIVACY ACT OF 1974 (5 USC 552a) + the E-Government Act of 2002; (b) NIST SP 800-53 Rev 5 PT family (PT-1 to PT-7 - PII processing transparency + minimisation + retention + dispute + breach response + opt-out); (c) FIPS 199 / 200 + NIST 800-122 for protecting PII; (d) the System of Records Notice (SORN) for federal record systems containing PII; (e) the Privacy Impact Assessment (PIA) requirement under E-Gov Act Section 208. FEDRAMP PRIVACY-SPECIFIC REQUIREMENTS: (a) PIA + SORN preparation as part of the authorization package; (b) PII minimisation + retention per agency policy; (c) PII breach notification per agency + US-CERT + OMB M-17-12 (Breach Response Guidance); (d) GAO + Inspector General audit-readiness for PII handling; (e) AGENCY-SPECIFIC PII rules (HIPAA for HHS + IRS + Census etc.) flow through to FedRAMP-authorized CSPs serving those agencies. The 2024-2025 FedRAMP modernization emphasises privacy + PII + civil-rights considerations.

Other controls in FedRAMP: Baseline Selection (Low, Moderate, High, LI-SaaS) and Control Overlay Parameters

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.