FISMA
FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status

FISMA FISMA-FedRAMP-Cloud-Coordination: FedRAMP for Cloud Services + 800-37 ATO Integration

FISMA + FedRAMP coordination for cloud services. FEDRAMP (Federal Risk and Authorization Management Program) operationalizes FISMA for CLOUD SERVICES used by federal agencies (established by OMB Memorandum M-11-30 + modernized by M-24-15 of July 2024). FedRAMP baselines (Low + Moderate + High + LI-SaaS) align with FIPS 199 + NIST 800-53 Rev 5 + FedRAMP-specific overlay parameters. FedRAMP authorization paths: JAB AUTHORIZATION (DOD + DHS + GSA P-ATO); AGENCY AUTHORIZATION (individual agency ATO); FedRAMP Marketplace + 3PAO accreditation. CLOUD-FIRST POLICY: agencies should prefer cloud services for new IT investments + use FedRAMP-authorized CSPs. CMMC (Cybersecurity Maturity Model Certification) Programme for DOD contractors: 3 levels + 3rd-party assessment + integration with NIST SP 800-171 Rev 3. FedRAMP Moderate + High frameworks VERIFIED separately in the graph against NIST 800-53 Rev 5 OSCAL. INTEGRATION: agency RMF authorization (NIST 800-37) leverages FedRAMP P-ATO + Agency ATO for cloud components; agency continuous monitoring incorporates FedRAMP ConMon + 3PAO assessment + Significant Change Request workflow.

Maintained by Gerard BlokdykControl text last updated

Other controls in FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.