FedRAMP
Standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by U.S. federal agencies.
- Authorized cloud service provider (Moderate or High baseline)
- NIST SP 800-53 control implementation and continuous monitoring
- US-based data residency and cleared personnel where required
- Documented SSP, POA&M, and annual assessments by a 3PAO