FedRAMP security controls

E1023779

FedRAMP security controls are a standardized set of baseline security requirements that U.S. federal agencies use to assess and authorize cloud service providers for handling government data.

All labels observed (8)

How this entity was disambiguated

Statements (48)

Predicate Object
instanceOf U.S. federal government standard
information security requirement set
security control baseline
administeredBy FedRAMP Program Management Office
alignedWith Federal Information Security Modernization Act
NIST Risk Management Framework
appliesTo Infrastructure as a Service offerings for federal agencies
Platform as a Service offerings for federal agencies
Software as a Service offerings for federal agencies
cloud service providers
basedOn NIST SP 800-53 security controls
linked to: NIST SP 800-53
evaluationMethod security assessment by Third Party Assessment Organizations
governs federal information in cloud computing environments
hasComponent FedRAMP High baseline
FedRAMP Low baseline
linked to: FedRAMP Low

FedRAMP Moderate baseline
linked to: FedRAMP Moderate
includes access control requirements
audit and accountability requirements
configuration management requirements
contingency planning requirements
incident response requirements
management security controls
operational security controls
risk assessment requirements
security assessment and authorization requirements
system and communications protection requirements
system and information integrity requirements
technical security controls
jurisdiction United States federal government
objective ensure consistent security posture across federal cloud services
standardize security assessment of cloud services
partOf Federal Risk and Authorization Management Program
purpose assess cloud service provider security
protect U.S. government data in cloud environments
support authorization of cloud services for federal use
requires continuous monitoring of cloud systems
documented security policies and procedures
independent security assessment
system security plan documentation
scope availability of federal information in the cloud
confidentiality of federal information in the cloud
integrity of federal information in the cloud
targetData federal information categorized as High impact
federal information categorized as Low impact
federal information categorized as Moderate impact
usedBy U.S. federal agencies
usedFor FedRAMP Authorization to Operate
linked to: FedRAMP Agency ATO

FedRAMP Provisional Authorization to Operate

How these facts were elicited

Referenced by (10)

Full triples — surface form annotated when it differs from this entity's canonical label.

NIST SP 800-53 mappingAvailableTo FedRAMP security controls
Joint Authorization Board usesFramework FedRAMP security baselines
linked to: FedRAMP security controls
Third Party Assessment Organizations assessmentBasis FedRAMP security baselines
linked to: FedRAMP security controls
FedRAMP Agency ATO constrainedBy FedRAMP baseline controls
linked to: FedRAMP security controls
FedRAMP High impact level hasControlBaseline FedRAMP High security control baseline
linked to: FedRAMP security controls
FedRAMP High impact level governedBy FedRAMP High Baseline Requirements
linked to: FedRAMP security controls
FedRAMP High impact level governedBy FedRAMP High Security Controls Baseline document
linked to: FedRAMP security controls
FedRAMP Marketplace package conformsTo FedRAMP documentation standards
linked to: FedRAMP security controls
FedRAMP Marketplace package relatedTo FedRAMP security assessment framework
linked to: FedRAMP security controls