The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring of cloud products and services. FedRAMP High establishes the highest level of stringency for handling the U.S. government’s most sensitive unclassified data. Compliance is mandated for all federal agencies and their cloud service providers.
FedRAMP controls are derived from the 5th revision of the National Institute of Standards and Technology (NIST) Special Publication 800-53–a definitive catalog of technical, operational, and management security and privacy controls. The controls encompass 18 out of 20 families of the NIST 800-53 framework, covering areas such as Access Control (AC), Audit and Accountability (AU), Contingency Planning (CP), and Incident Response (IR).
