The Federal Risk Management and Authorization Program (FedRAMP) is a US government program that establishes a standard approach to validating the “security” of cloud service providers.
Fedramp compliance organizations are considered “Authorized for Work” (ATO), which means they are “pre-approved” providers for federal agencies looking to purchase their cloud services. No additional security clearance is required for other agents to buy this service.
The engine behind FedRAMP is the December 2011 OMB directive, which requires federal agencies to move all existing and new services to the cloud to reduce billions of dollars in costs.
What was the motive behind the development of the fedramp certificate?
Why did the US government develop fedramp certification instead of using an existing and well-tested security standard or framework such as ISO 27001, SOC 2 or Cloud Control Matrix (CCM)?
FedRAMP isn’t new – it’s a formal “certification process” using the NIST/FISMA information security framework (specifically NIST 800-37 and NIST 800-53) that the US government has been operating since 2002. Fedramp certified companies add the concept of independent third-party validation /objective of supplier security posture (equivalent to the registrar in ISO 27001 or CPA in SOC 2).
How can one know if they require fedramp certification?
Now that it came to know about what is federal certification now, let’s talk about how one can see if they require certification.
Any company that offers services that involve processing information from a US government agency operating in an environment not controlled by that agency is a CSP. The “traditional” delivery model, including infrastructure as a service (IaaS), platform as a service (PaaS), and hardware as a service (HaaS), is cited explicitly through maintaining fedramp requirements such as the.cio.gov cloud. FedRAMP hybrid also considers cloud services.
Thus, almost any company that provides data processing services to federal agencies can become CSP. Learn more about what is fedramp and cast your assistance over the marketplace today.
What are the goals of federal certification?
•Reduce costs by billions of dollars by moving existing and new services to the cloud
•Increase confidence in the security of cloud solutions
•Achieve consistent security review through an agreed set of core standards and an accredited, independent third-party assessment organization
•Increase automation and near real-time data for continuous monitoring
So these are some goals of federal certification.
For more information, visit https://ignyteplatform.com/fedramp-authorization/
###
