Federal Risk and Authorization Program (FedRAMP)

Part of the TechTarget Network of Enterprise IT Web Sites

Search our IT-specific encyclopedia for:
 
Browse alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #
All Categories Government IT

Federal Risk and Authorization Program (FedRAMP)

The Federal Risk and Authorization Program (FedRAMP) is a risk management program for large outsourced and multi-agency information systems used by the U.S. government.  FedRAMP authorizes and continuously monitors IT services that are used by multiple federal departments and agencies.

FedRAMP was created to support the government’s cloud computing plan. It is intended to facilitate the adoption of cloud computing services amongst federal agencies by evaluating those services offered by vendors on behalf of the agencies. The evaluations will be based on a unified risk management process that includes security requirements agreed upon by the federal departments and agencies.  Because the services are vetted by FedRAMP, each agency does not need to conduct its own risk management program. This reduces duplication of effort, the time involved in acquiring services and costs. However, agencies are still encouraged to evaluate services further based on their own use, and privacy and security requirements. The plan is to eventually expand FedRAMP beyond cloud services.

Vendors cannot directly request FedRAMP authorization. In order to be evaluated, an agency must sponsor the vendor’s system/service and submit it to FedRAMP for review by a joint authorization board. In the case of cloud services, the joint authorization board consists of senior executives and technical staff members from the Defense and Homeland Security departments, the General Services Administration and the sponsoring agency.

While FedRAMP is intended to be a government-wide initiative, agencies’ involvement is voluntary.

Learn more about FedRAMP:

Tim Mather explains how FedRAMP fits in with other cloud governance initiatives

Last updated on: Jul 07, 2010
Editorial Director: Margaret Rouse

>  Enterprise Software related Research & News
>  White Papers for the Retail Industry

Are you a Know-IT-All?
This is the certification of a product or specification to indicate that it meets regulatory standards.
a. homologation
b. collocation

word of the day Sign up for the Word of the Day
twitter Follow us on Twitter
Editorial director:


WORD OF THE DAY...
context-aware network access control
LEARN MORE ABOUT...
Windows 8
AccessChk
AccessEnum
Microsoft Windows Server 2008
Windows Server 2008 R2
icacls
mechanical refrigeration
mobile middleware
PCI DSS 2.0
PCI DSS User Group
Raspberry Pi ($35 computer)
HTML 5 client
persistent desktop
nonpersistent desktop
Microsoft System Center Virtual Machine Manager 2012
RemoteFX
Windows Thin PC
polyfill
computer room air handler (CRAH
arc flash
electric arc
WhatIs.com RSS Feeds
About Us   |   Contact Us   |   For Advertisers   |   For Business Partners   |   Reprints   |   RSS   |   Awards
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts