Parameter

What is FedRAMP?

Federal Risk and Authorization Management Program

What FedRAMP is, the Low, Moderate and High baselines, the authorization path, and its penetration testing and continuous monitoring demands.

01Introduction

To sell cloud services to US federal agencies, you need FedRAMP authorization. It's one of the most demanding security programs a cloud provider can take on, and one of the most valuable.

02What is FedRAMP?

The Federal Risk and Authorization Management Program (FedRAMP) is a US government program that standardizes security assessment, authorization and continuous monitoring for cloud products used by federal agencies. It is based on NIST SP 800-53 controls at Low, Moderate or High impact baselines.

Authorization requires an assessment by an accredited Third Party Assessment Organization (3PAO), including penetration testing to FedRAMP's guidance, followed by monthly continuous monitoring. SBOMs are increasingly expected under federal software requirements.

03How FedRAMP works

FedRAMP is a long process with an ongoing tail.

  1. 1.

    Prepare

    Choose a baseline, find an agency sponsor and write the System Security Plan.

  2. 2.

    Assess

    A 3PAO tests the controls, including a penetration test covering defined attack vectors.

  3. 3.

    Authorize

    The agency or FedRAMP board reviews the package and issues an authorization.

  4. 4.

    Continuous monitoring

    Monthly vulnerability scanning, plan-of-action tracking and annual assessments.

04Threats and risks

FedRAMP punishes gaps in continuous monitoring.

  • POA&M backlog

    Open vulnerabilities past remediation deadlines put the authorization at risk.

  • Boundary drift

    New services or data flows outside the authorized boundary.

  • Supply chain scrutiny

    Federal requirements for software provenance and component inventory. See software supply chain security.

  • Testing depth

    Pentests have to cover the attack vectors FedRAMP specifies, not just a scan.

05How Parameter helps

Parameter helps keep the continuous part of FedRAMP continuous. See FedRAMP penetration testing.

  • Ongoing testing

    The pentesting agents test between annual assessments, so issues are found before the 3PAO does.

  • Proven remediation

    Retests on fix give evidence for closing plan-of-action items.

  • Signed SBOMs

    Supply Chain regenerates a signed inventory on every build.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your FedRAMP program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.