FedRAMP, without the spreadsheets.
Prepare your cloud service for US government authorisation.
What is FedRAMP?
FedRAMP standardises how US federal agencies assess and authorise cloud services. Its baselines are built on NIST SP 800-53 Rev. 5 and assessed by an accredited third-party assessment organisation (3PAO), followed by continuous monitoring once authorised.
Who needs it
- Cloud service providers selling to US federal agencies
- SaaS companies pursuing public-sector revenue
What FedRAMP looks at
Authorisation boundary
A clear definition of the system and everything inside it.
System security plan
How each baseline control is implemented.
Continuous monitoring
Monthly vulnerability scanning and plan of action and milestones (POA&M) reporting.
How Beviso gets you there
- FedRAMP controls pre-loaded with evidence shared with NIST 800-53
- Continuous evidence collection that suits ongoing monitoring
- Vulnerability evidence from cloud and scanning integrations
10 FedRAMP controls, ready on day one
These controls are loaded when you enable FedRAMP, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
AC-2
Account Management
Manage information system accounts in accordance with Federal requirements, including establishing, reviewing, modifying, and removing accounts.
Evidence from
- Okta
- Google Workspace
- Microsoft Azure
- AWS
- GitHub
AC-6
Least Privilege
Employ the concept of least privilege, allowing only authorized accesses for users which are necessary to accomplish assigned tasks.
Evidence from
- AWS
- Okta
- HashiCorp Vault
- Microsoft Azure
IA-2(1)
MFA — Privileged Accounts
Implement MFA for access to privileged accounts as required by FedRAMP.
Evidence from
- Okta
- Duo
- Microsoft Azure
- JumpCloud
AU-2
Audit Events
Identify the types of events that the system is capable of logging, including all FedRAMP-required events.
Evidence from
- Datadog
- AWS
- Okta
- Splunk
- HashiCorp Vault
CA-7
Continuous Monitoring
Develop a continuous monitoring strategy and implement a continuous monitoring program.
Evidence from
- Datadog
- AWS
- Splunk
- Grafana
- Lacework
CM-6
Configuration Settings
Establish and document configuration settings for IT products employed within the information system following FedRAMP baseline.
Evidence from
- Terraform Cloud
- AWS
- Doppler
- Jamf
- Kandji
IR-4
Incident Handling
Implement an incident handling capability including US-CERT reporting as required by FedRAMP.
Evidence from
- PagerDuty
- ServiceNow
- Jira
RA-5
Vulnerability Scanning
Scan for vulnerabilities in the information system and hosted applications at the FedRAMP-required frequency.
Evidence from
- Snyk
- Wiz
- Qualys
- Rapid7
- AWS
SC-7
Boundary Protection
Monitor and control communications at the external boundary and key internal boundaries within FedRAMP authorization boundary.
Evidence from
- Cloudflare
- AWS
SI-2
Flaw Remediation
Identify, report, and correct information system flaws within FedRAMP-defined timeframes (critical: 30 days).
Evidence from
- Snyk
- GitHub
- Qualys
- Wiz
- SonarCloud
FedRAMP questions
- Is Beviso itself FedRAMP authorised?
- No. Beviso is EU-hosted and helps you prepare and organise evidence for your own FedRAMP effort.
Often run alongside FedRAMP
NIST 800-53
Work from the control catalogue behind US federal security.
CMMC
Protect Controlled Unclassified Information and stay eligible for defence contracts.
NIST CSF 2.0
Measure and improve your security programme against a common language.
SOC 2
Give US customers the SOC 2 report their procurement team asks for.
Start your FedRAMP programme today.
Free while Beviso is in beta. No credit card required.
Get started free