If your organization is currently seeking FedRAMP Certification assistance, read on.
The Federal Risk and Authorization Management Program (FedRAMP) was created to provide a standardized approach to security assessment, authorization and continuous monitoring for cloud products and services being utilized by the federal government.
Any Cloud Service Provider (CSP) working with the federal government. Per an OMB memorandum, any cloud service offering (CSO) holding federal data must have a FedRAMP authorization. In addition to the mandate by OMB, many organizations are considering a FedRAMP authorization due to requirements from potential federal customers and overall the ability to market the service(s) on the FedRAMP Marketplace overall.
Organizations seeking an authorization will work closely with the FedRAMP Program Management Office (PMO). The PMO is responsible for providing a consistent process for all stakeholders, enabling services reuse across the government, and providing a secure repository and marketplace. It also acts as an overall key partner to CSPs going through the authorization process.
The ultimate goal of the FedRAMP authorization process is to achieve an Authority to Operate (ATO) status. There are two distinct paths to do so:
1. Joint Authorization Board (JAB)
The JAB is the primary governance and decision-making body for FedRAMP. They define and establish the FedRAMP baseline system security controls and the accreditation criteria for the Third-Party Assessment Organizations (3PAOs), but they also work with the PMO to ensure controls are incorporated consistently for all security assessments and authorizations.
Any CSP utilizing JAB authorization path for their CSO has to go through a bi-annual prioritization process, which includes the submission of a business plan and a review by the JAB, which will look for the CSOs most likely to be leveraged by multiple governmental agencies. The end result of a JAB authorization is a Provisional Authority to Operate (P-ATO).
JAB Authorization Path source.fedramp.gov
2. Agency Sponsorship
A CSP that has a relationship with a federal agency (note: state and local government agencies are not qualified to be a sponsor) can work directly with them to pursue an Authority to Operate (ATO), where the agency will support the CSP through the acquisition and FedRAMP authorization process. Ultimately, the Agency’s Authorizing Official (AO) must review and accept the risk associated with the use of the specific cloud service offering. The Agency sponsor will also perform the monthly and annual deliverables provided by the CSP (covered in “Maintaining a FedRAMP authorization” below).
Agency Authorization Path source.fedramp.gov
Although both paths lead to an authorization under FedRAMP, the two have significantly different processes. At RISCPoint, we recommend exploring the Agency sponsorship path, which allows for risk acceptance while helping organizations avoid the JAB prioritization process. In certain cases, this path also enables your CSO to go directly through the 3PAO Security Assessment (thereby potentially skipping a FedRAMP Readiness Assessment), which may allow for a quicker authorization path.
Understanding your CSO’s and organization’s preparedness and viability for the FedRAMP authorization process is crucial. A CSP should be prepared to demonstrate whether its service is operational or is under development, in addition to the extent of the current demand for the service in the federal market.
That being said, a few key items related to the CSP’s cloud offering must be checked off at the onset of the authorization process:
During this last step, many organizations leverage documentation developed for other compliance frameworks (SOC 1, SOC 2, HITRUST, FISMA, PCI, ISO 27001, etc.). Understanding the overlap between the different standards, as well as the differences between them, becomes that much more important. In FedRAMP’s case, this could be quite significant.
At RISCPoint, we specialize in developing custom roadmaps for all of our clients. Our team of experienced FedRAMP advisors allows for a much more efficient process, a quicker time to authorization, and, overall, a more optimized compliance posture permits organizations to maintain multiple standards, while minimizing the level of effort and budget spent on compliance.
It is also worthy to note that the preparation phase is often where most organizations fall short of the rigorous expectations set forth by FedRAMP. By partnering with FedRAMP experts, organizations are not only able to complete the process in the most efficient manner, but they can avoid common pitfalls with FedRAMP, such as not accurately defining the authorization boundary, not having FIPS 140-2 validated encryption algorithms, not implementing MFA appropriately, poor configuration documentation and immature management processes, not applying the right resources up front, and many others.
Once you’ve obtained your FedRAMP Authorization, the FedRAMP journey isn’t over. We don’t get to pack our bags and just go home.
Moving forward, all authorized CSPs must provide monthly, continuous monitoring deliverables to the agencies using their service. These deliverables typically include, but are not limited to, an updated POA&M, scan results/reports, and system change information/requests, as agreed upon between the Agency and the CSP.
Each agency using the service reviews the monthly continuous monitoring deliverables, but they do not need to be shared with FedRAMP. Additionally, a CSP must employ a 3PAO to complete an annual security assessment to ensure that the risk posture of the system is maintained at an acceptable level throughout the lifecycle of the system.
A lot of organizations rely on experienced FedRAMP advisors, such as RISCPoint, to assist in managing or executing their continuous monitoring responsibilities because of our proven track record, tailored solutions, and customer-first approach. We achieve this success by:
Have questions about how our work can work for you? Get in touch with us with the form below.
Subscribe to our newsletter and get the latest cybersecurity insights, updates, and event invitations delivered straight to your inbox. Join our community and empower your security journey with RISCPoint's expert knowledge.
Join our newsletter for updates. Terms.