FedRAMP (Federal Risk and Authorization Management Program) is an assessment and authorization process which federal agencies use to ensure the security of cloud computing services and products. If you belong to a cloud company that wishes to provide services in the federal space, you could work towards becoming a FedRAMP Authorized Cloud Service Provider (CSP). This authorization will likely improve your chances of winning any government contract, but is required for consideration for federal agencies.
FedRAMP is based on the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Security and Privacy Controls, as well as low/moderate categorization of Federal Information Processing Standard 199 (FIPS 199). SP800-53 is the control set that is used by federal agencies themselves to meet the FISMA regulations and is currently being updated to revision 5. The Federal information Processing Standard (FIPS 199) is the standard for document processing, encryption algorithms and other information technology standards for use within non-military government agencies and by government contractors and vendors. FedRAMP standards are more stringent than NIST.
If you are a cloud service provider and wish to sell your services to federal agencies, then you need to be aware of FedRAMP. The federal government spends billions of dollars every year on cloud services. FedRAMP certification brings about a level of standardization that will allow you to compete on a more even playing field with other authorized cloud service providers. Your Chief Information Security Officer (CISO) would be a key player to coordinate this initiative for your company.
If you, as a cloud services provider, decide that you want to obtain FedRAMP authorization for your company, here are some basic steps that you can follow:
Once authorized, you will need to submit monthly continuous monitoring deliverables and reports to the agencies that are using your services. You must also complete an annual Security Risk Assessment to maintain proper Risk Assessment Status and update documentation in the FedRAMP secure repository.
At present, while 24by7Security is not yet a 3PAO, we can assist you in getting ready for authorization by conducting an assessment of current controls in place for your cloud environment and assisting with putting in controls to meet SP800-53 requirements. Don't Risk it, Secure it!