FedRAMP Rev 5
FedRAMP: Program, Authorization Paths and PMO Governance

FedRAMP Rev 5 FedRAMP-Program: FedRAMP Program establishment, PMO and authorization paths

FedRAMP was established in 2011 by OMB Memorandum M-11-30 + implementing FISMA for cloud services used by US federal agencies. The FedRAMP Program Management Office (PMO) is housed within the General Services Administration (GSA). Two authorization paths exist: (a) JAB AUTHORIZATION - the Joint Authorization Board comprises DOD + DHS + GSA + reviews CSPs against the highest risk + most-utilised cloud services + issues a Provisional Authority to Operate (P-ATO); (b) AGENCY AUTHORIZATION - any federal agency may sponsor a CSP through the FedRAMP authorization process + issue an agency Authority to Operate (ATO) recognised across the federal government once accepted via the FedRAMP Marketplace. Both paths require: completion of the FedRAMP Authorization Package (SSP + SAR + POA&M + ConMon Plan + Inventory + Boundary Diagram + Configuration Management + Incident Response + others); 3PAO assessment; PMO review + acceptance into the FedRAMP Marketplace. The FedRAMP Authorization is the primary federal cloud-authorization credential; non-authorized CSPs cannot be used by federal agencies for sensitive data per OMB policy.

Maintained by Gerard BlokdykControl text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.