The Federal Risk and Authorization Management Program (FedRAMP) is a U.S. government-wide program that delivers a standard approach to the security assessment, authorization and continuous monitoring for cloud products and services. The governing bodies of FedRAMP include the Office of Management and Budget (OMB), U.S. General Services Administration (GSA), U.S. Department of Homeland Security (DHS), U.S. Department of Defense (DOD), National Institutes of Standards & Technology (NIST) and the Federal CIO Council.
FedRAMP uses the NIST Special Publication 800 series and requires cloud service providers to receive an independent security assessment conducted by a third-party assessment organization (3PAO) to ensure authorizations are compliant with the Federal Information Security Management Act (FISMA). Cloud providers who want to offer their products and services to the US government must demonstrate FedRAMP compliance. For additional information on FedRAMP requirements please visit www.FedRAMP.gov.
Amazon Web Services (AWS) offers the following FedRAMP compliant systems:
AWS GovCloud (US), has been granted a Joint Authorization Board Provisional Authorization (JAB P-ATO) for high impact level. The services covered are: EC2, EBS, IAM, S3, and VPC.
AWS US East-West, has been granted multiple Agency Authorizations for moderate impact level. The services covered are EC2, EBS, IAM, Redshift, S3, and VPC.