FedRAMP High impact level

E1023367

FedRAMP High impact level is the most stringent FedRAMP security categorization, applied to cloud systems whose compromise could severely affect an agency’s operations, assets, or individuals.

All labels observed (3)

How this entity was disambiguated

Statements (48)

Predicate Object
instanceOf FedRAMP impact level
information security categorization
alignedWith NIST Risk Management Framework
appliesTo Infrastructure-as-a-Service offerings
Platform-as-a-Service offerings
Software-as-a-Service offerings
cloud information systems
federal information systems hosted in the cloud
associatedWith severe adverse effect on individuals
severe adverse effect on organizational assets
severe adverse effect on organizational operations
basedOn FIPS 199 security categorization
NIST SP 800-60
definedBy FedRAMP Program Management Office
governedBy FedRAMP High Baseline Requirements
FedRAMP High Security Controls Baseline document
FedRAMP Security Assessment Framework
hasControlBaseline FedRAMP High security control baseline
hasHigherStringencyThan FedRAMP Low impact level
linked to: FedRAMP Low

FedRAMP Moderate impact level
hasImpactLevel High
hasPurpose to protect highly sensitive federal information in cloud environments
hasRiskCategory High
hasStricterControlsThan FedRAMP Low baseline
linked to: FedRAMP Low

FedRAMP Moderate baseline
linked to: FedRAMP Moderate
partOf FedRAMP
Federal Risk and Authorization Management Program
requires authorization by a federal agency or the Joint Authorization Board
configuration management controls
continuous monitoring
documented security policies and procedures
encryption of data at rest
encryption of data in transit
enhanced availability protections
enhanced confidentiality protections
enhanced integrity protections
formal risk assessments
incident response capabilities
independent third-party assessment
multi-factor authentication
strong access control measures
vulnerability scanning
usedBy U.S. federal agencies
usedFor systems where loss of availability could have severe or catastrophic adverse effect
systems where loss of confidentiality could have severe or catastrophic adverse effect
systems where loss of integrity could have severe or catastrophic adverse effect
usedInContextOf U.S. federal cloud authorizations
usesControlBaselineFrom NIST SP 800-53

How these facts were elicited

Referenced by (5)

Full triples — surface form annotated when it differs from this entity's canonical label.

FedRAMP Moderate relatedStandard FedRAMP High
linked to: FedRAMP High impact level
Azure Government compliesWith FedRAMP High
linked to: FedRAMP High impact level
FedRAMP Low relatedBaseline FedRAMP High
linked to: FedRAMP High impact level
FedRAMP security controls hasComponent FedRAMP High baseline
linked to: FedRAMP High impact level