FedRAMP takes applications for service providers

Cloud service providers in the government and the private sector can apply to have the security of their cloud-based systems tested starting June 6.

The Federal Risk Authorization Management Program, or FedRAMP, will accept applications from service providers for the security assessment process on an on-going basis after the start date.

In May, the General Services Administration released a list of nine accredited third-party assessment organizations—or 3PAOs for short—that will do initial assessments and test the controls of providers per FedRAMP requirements. The 3PAOs will have an ongoing part in ensuring providers meet requirements.

FedRAMP offers a standard approach for conducting security assessments of cloud systems based on a set of security controls and consistent processes. The Office of Management and Budget requires agencies buying cloud services to use FedRAMP.

After receiving the initial applications, FedRAMP program officials will develop a queue order in which to review authorization packages. Officials will prioritize secure Infrastructure as a Service (IaaS) solutions, contract vehicles for commodity services, and shared services that align with the administration’s Cloud First policy.

About the Author

Matthew Weigelt is a freelance journalist who writes about acquisition and procurement.

Featured

  • Image: Shutterstock

    COVID, black swans and gray rhinos

    Steven Kelman suggests we should spend more time planning for the known risks on the horizon.

  • IT Modernization
    businessman dragging old computer monitor (Ollyy/Shutterstock.com)

    Pro-bono technologists look to help cash-strapped states struggling with legacy systems

    As COVID-19 exposed vulnerabilities in state and local government IT systems, the newly formed U.S. Digital Response stepped in to help.

Stay Connected