By IT Brew Staff
less than 3 min read
Definition:
The FedRAMP Authorization Act, passed in December 2022, established the government-wide program as “a standardized, reusable approach” to security authorization of cloud tools that process and store agencies’ unclassified information. It is an important program for any cloud vendor that interacts with US government data as part of its business.
FedRAMP’s “do once, use many times” approach aims to save federal agencies time and resources by reducing duplicative work (like multiple assessments), establishing public–private partnerships, and writing transparent standards. The new version, FedRAMP 20x, replaces the Rev. 5, an examination aligned with NIST’s 800-53 Rev. 5 baselines; after June 2027, no new Rev. 5 applications will be accepted.
Whereas FedRAMP Rev. 5 encouraged companies to devote considerable time and resources to building government-specific cloud services, FedRAMP 20x is aimed at cloud services built atop FedRAMP-compliant cloud infrastructure, and prods the government to adopt commercial cloud services.
FedRAMP 20x has various classifications for third-party cloud services and tools, ranging from A (adequate for use in pilots or extremely low-risk use cases) to Class D (which still needs to be developed). Cloud providers determine their own service-specific security goals, measures, engineering methods, and outcomes, including a measurable “KSI,” or key security indicator—an independent assessor then determines if the objectives are valid, honest, effective, and implemented as described.
As part of that review, the assessor examines security capabilities, tracing important validation questions along the way, including: What resources and data are in scope? Where does that data originate? What codes, queries, and human efforts lead to the result? What is a failure, and how does the provider respond to a failure?
Cloud categories outside of FedRAMP’s scope include:
- Information systems “only used for a single agency’s operations, hosted on cloud infrastructure or platform,” and not offered as a shared service
- Social media and communications platforms
- Search engines
- Available services that provide commercially available information to agencies, but do not collect federal information