FedRAMP was established in 2011 by OMB Memorandum M-11-30 + implementing FISMA for cloud services used by US federal agencies. The FedRAMP Program Management Office (PMO) is housed within the General Services Administration (GSA). Two authorization paths exist: (a) JAB AUTHORIZATION - the Joint Authorization Board comprises DOD + DHS + GSA + reviews CSPs against the highest risk + most-utilised cloud services + issues a Provisional Authority to Operate (P-ATO); (b) AGENCY AUTHORIZATION - any federal agency may sponsor a CSP through the FedRAMP authorization process + issue an agency Authority to Operate (ATO) recognised across the federal government once accepted via the FedRAMP Marketplace. Both paths require: completion of the FedRAMP Authorization Package (SSP + SAR + POA&M + ConMon Plan + Inventory + Boundary Diagram + Configuration Management + Incident Response + others); 3PAO assessment; PMO review + acceptance into the FedRAMP Marketplace. The FedRAMP Authorization is the primary federal cloud-authorization credential; non-authorized CSPs cannot be used by federal agencies for sensitive data per OMB policy.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.