Understanding the Multiple Versions of the FedRAMP ATOs

From: DataPipe.com

The purpose of FedRAMP is simple – to act as a common set of security controls that can be accepted government-wide. However, since the July 2014 FedRAMP rollout, this security risk management program has gotten increasingly complex.

With the initial FedRAMP rollout, the Joint Authorization Board (JAB), which is comprised of the CIOs from the Department of Homeland Security (DHS), Department of Defense (DoD), and the General Services Administration (GSA), began to assess cloud platforms against the common set of security controls. Not long after, a second path was added, Agency FedRAMP Authorization, which allowed an agency to issue an authority to operate (ATO) after assessing the security controls. Finally, a third option was added, the CSP Supplied Package.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *