OMB Releases FedRAMP Policy Memo
OMB Releases FedRAMP Policy Memo
Currently the Federal government suffers from duplicative, inconsistent, time consuming, costly, and inefficient cloud security risk management approaches. There is little incentive to leverage existing Authorizations to Operate (ATOs) among agencies, with many preferring to perform their own ATOs when other agencies have approved the same cloud systems for secure use within their agencies.
Today, OMB released a policy memo establishing the Federal Risk and Authorization Management Program (FedRAMP) which will reduce the duplicative efforts, inconsistencies and cost inefficiencies when assessing and authorizing cloud systems. FedRAMP will provide a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services through standardized security requirements and controls.
FedRAMP is a government-wide effort, and represents the efforts of the Department of Defense (DoD), the Department of Homeland Security (DHS), the General Services Administration (GSA), the National Institute of Standards and Technology (NIST), and the Office of Management and Budget (OMB), amongst many others.
Some key FedRAMP benefits include:
- Saves significant cost, time and resources – do once, use many times
- Improves real-time security visibility
- Supports risk-based security management
- Provides transparency between government and cloud service providers (CSPs)
- Improves trustworthiness, reliability, consistency, and quality of the federal security authorization process
To learn more about FedRAMP, please visit www.FedRAMP.gov.


