- Full name
- Federal Risk and Authorization Management Program
- Region
- United States federal government
- Applies to
- Cloud service providers selling to US federal agencies, and the agencies that consume those services. FedRAMP baselines (Low, Moderate, High) inherit from NIST SP 800-53.
FedRAMP standardises the security assessment and authorisation of cloud services for US federal use. The control baselines derive from NIST SP 800-53, with FedRAMP-specific parameters and additional requirements. The Access Control (AC) and Identification and Authentication (IA) families are the largest single sources of evidence in any FedRAMP package, and the area where continuous-monitoring deviations are most often found.