FedRAMP Low

E1023369

FedRAMP Low is a baseline security authorization level within the U.S. Federal Risk and Authorization Management Program designed for cloud systems handling the least sensitive federal information and requiring minimal security controls.

All labels observed (3)

Label Occurrences
FedRAMP Low baseline 2
FedRAMP Low canonical 1
FedRAMP Low impact level 1

How this entity was disambiguated

Statements (49)

Predicate Object
instanceOf FedRAMP security baseline
information security standard
appliesTo cloud service offerings
federal information systems
assessmentPerformedBy Third Party Assessment Organization
authorizationBoundary applies to systems categorized as low impact under FIPS 199
authorizationType security authorization baseline
basedOnStandard FIPS 199
NIST SP 800-53
controlFamilyCoverage access control
audit and accountability
configuration management
contingency planning
identification and authentication
incident response
maintenance
media protection
physical and environmental protection
risk assessment
system and communications protection
system and information integrity
countryOfOrigin United States
documentationRequirement Plan of Action and Milestones
Security Assessment Plan
Security Assessment Report
System Security Plan
governingBody FedRAMP Program Management Office
impactCategory availability low
confidentiality low
integrity low
includes management security controls
operational security controls
technical security controls
informationSensitivity least sensitive federal information
objective to ensure adequate security for low-impact federal cloud services
overseenBy Joint Authorization Board
U.S. General Services Administration
partOf Federal Risk and Authorization Management Program
purpose to define minimum security requirements for low-impact federal cloud systems
relatedBaseline FedRAMP High
FedRAMP Moderate
requires minimal security controls compared to FedRAMP Moderate and High
riskLevel low impact to individuals
low impact to organizational assets
low impact to organizational operations
securityImpactLevel low
usedBy U.S. federal agencies
cloud service providers seeking FedRAMP authorization
usesControlBaselineFrom NIST SP 800-53 low baseline
linked to: NIST SP 800-53

How these facts were elicited

Referenced by (4)

Full triples — surface form annotated when it differs from this entity's canonical label.

FedRAMP Moderate relatedStandard FedRAMP Low
FedRAMP High impact level hasHigherStringencyThan FedRAMP Low impact level
linked to: FedRAMP Low
FedRAMP High impact level hasStricterControlsThan FedRAMP Low baseline
linked to: FedRAMP Low
FedRAMP security controls hasComponent FedRAMP Low baseline
linked to: FedRAMP Low