CGRC · Question #264
Which of the following BEST describes a government-wide standard for security Assessment and Authorization (A&A) and continuous monitoring for cloud products, which is mandatory for federal agencies…
The correct answer is C. Federal Risk and Authorization Management Program (FedRAMP). The Federal Risk and Authorization Management Program (FedRAMP) is the mandatory government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies. It ensures…
Question
Which of the following BEST describes a government-wide standard for security Assessment and Authorization (A&A) and continuous monitoring for cloud products, which is mandatory for federal agencies and cloud service providers (CSP)? Response:
Options
- ATrusted Computer System Evaluation (TCSEC)
- BFederal Information Technology Acquisition Reform Act (FITARA)
- CFederal Risk and Authorization Management Program (FedRAMP)
- DNational Institute of Standard and Technology (NIST)
How the community answered
(50 responses)- A2% (1)
- B2% (1)
- C90% (45)
- D6% (3)
Why each option
The Federal Risk and Authorization Management Program (FedRAMP) is the mandatory government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies. It ensures that cloud services meet specific security requirements before being adopted by government entities.
TCSEC (Trusted Computer System Evaluation Criteria) is an outdated standard from the 1980s, superseded by Common Criteria, and is not specifically for cloud products or mandatory for federal agencies today.
FITARA (Federal Information Technology Acquisition Reform Act) focuses on improving how the government acquires and manages IT, but it is not a standard for security A&A and continuous monitoring of cloud products.
FedRAMP (Federal Risk and Authorization Management Program) is explicitly designed as a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services, making it mandatory for federal agencies and Cloud Service Providers (CSPs). This streamlines the process and ensures consistent security standards across government cloud adoption.
NIST (National Institute of Standards and Technology) develops many security standards and guidelines (like SP 800-53), but NIST itself is an organization, not the specific program described for cloud A&A and continuous monitoring. FedRAMP heavily leverages NIST guidelines.
Concept tested: FedRAMP purpose and scope
Source: https://www.fedramp.gov/
Topics
Community Discussion
No community discussion yet for this question.