1 min read

GovRAMP Celebrates the Passage of FedRAMP Authorization Act

GovRAMP Celebrates the Passage of FedRAMP Authorization Act

Earlier this month, President Biden signed into law H.R. 7776, which includes codification of the FedRAMP program. The passage of the FedRAMP Authorization Act is something to be celebrated and recognizes the hard work by dedicated leaders at FedRAMP and its stakeholders.  For more than a decade, FedRAMP has championed the importance of ongoing verification of cloud security for third-party suppliers to the federal government.  

In many ways, it was the idea of FedRAMP that inspired GovRAMP's founding Steering Committee to form GovRAMP in 2020. 

GovRAMP is modeled in part after FedRAMP, both sharing control requirements based on the National Institute of Standards & Technology (NIST) SP 800-53 and both relying on independent audits by third party assessment organizations. Continuous monitoring and monthly reporting are hallmarks of both GovRAMP and FedRAMP.  

Just as FedRAMP exists to serve federal agencies, GovRAMP is designed to serve non-federal agencies from states to local governments and public pre-k through higher education jurisdictions and the providers who serve them. 

With the passage of the FedRAMP Authorization Act, the goals of FedRAMP and GovRAMP continue to align. 

A key provision in the FedRAMP Authorization Act is the idea of Agency Acceptance of ATOs, meaning agencies can recognize a FedRAMP Authorization to Operate (ATO) without the process of issuing their own ATO.   

GovRAMP is working toward the same goal among our growing list of participating government members.  

GovRAMP's standardized approach and centralized program management office allows providers to verify and report continuous monitoring once in order to serve many, giving governments shared access to critical information and enabling a more proactive approach to managing third party cyber risk.  

The only way to improve cybersecurity is to go forward together. 

Today, all levels of government rely on cloud products to help in the delivery and efficiency of government services. The responsibility of protecting the integrity of government and the securing of citizen data is not the government’s responsibility alone. The responsibility to ensure the highest level of cybersecurity rests also with the vendors who serve government.  

Working with programs like FedRAMP and GovRAMP, cloud service providers can help make a difference in moving toward a more secure future.   

Understanding Threats and Vulnerabilities in Government Cybersecurity

Understanding Threats and Vulnerabilities in Government Cybersecurity

In cybersecurity, especially in the public sector, clarity matters. Terms like “threat” and “vulnerability” are often used interchangeably, but they...

Read More
What Is Risk—And Why It Matters in Cybersecurity Risk Management for Government

What Is Risk—And Why It Matters in Cybersecurity Risk Management for Government

Risk isn’t just a technical concern. For both public and private sector organizations, it's a strategic consideration tied directly to trust,...

Read More
HRTec: Enabling Secure Government Infrastructure with GovRAMP

HRTec: Enabling Secure Government Infrastructure with GovRAMP

HRTec has long supported public sector organizations through its secure, scalable FedHIVE platform and Compliance as a Service model. As a GovRAMP...

Read More
GovRAMP and the Cost of Cybersecurity Ignorance

GovRAMP and the Cost of Cybersecurity Ignorance

As businesses evolve in the digital landscape, so do the threats they face. Investing in cybersecurity is critical, especially when doing business...

Read More
What You Need To Know About the Access Control (AC) Control Family

What You Need To Know About the Access Control (AC) Control Family

GovRAMP security standards and requirements are based on the National Institute of Standards and Technology (NIST) Special Publication 800-53 Rev. 4....

Read More
Cloud Security Compliance Mistakes and How to Avoid Them

Cloud Security Compliance Mistakes and How to Avoid Them

Securing cloud services and protecting consumer data is extremely important in today’s technology landscape. As more businesses rely on cloud...

Read More