Title | Summary | Categories | Link |
---|---|---|---|
3PAO Accreditation Process | GovRAMP recognized FedRAMP authorized third party assessment organizations (3PAOs) to conduct independent audits. | Governance | |
3PAO Package for Moderate Impact with CJIS Overlay | This package includes required templates and sample policies for every NIST 800-53 control family, along with templates for Rules of Behavior, Incident Response Plan, Configuration Management Plan, Information System Contingency Plan, and Supply Chain Risk Management. | ||
Appeals Committee Charter | The Appeals Committee serves as the adjudication board for the Program Management Office determinations. | Governance | |
Baseline Controls | This document provides the security control baselines. All of the security controls listed in the table are outlined in NIST 800-53 Rev. 4. (Retired October 1, 2024) | Baseline Requirements | |
Center for Digital Government Best Practice Guide for Cloud and As-a-Service Procurements | The Best Practice Guide was created to provide government and industry with consensus-based advice and terms and conditions for cloud solution procurement models. | Government Document | |
Continuous Monitoring Escalation Process | This document explains the actions taken when a service provider fails to maintain an adequate continuous monitoring program. | Continuous Monitoring | |
Continuous Monitoring Guide | Continuous monitoring review procedures outline the process to examine each monthly package. | Continuous Monitoring | |
Data Classification Tool | This document helps service providers and governments determine what GovRAMP security category requirements to use to ensure their data is protected. | Baseline Requirements | |
FedRAMP JAB Attestation | In an effort to provide recognition to those providers whose products have achieved a FedRAMP Authorization through Joint Authorization Board (JAB) approval, a new Federal JAB status has been created for providers who wish to list their product on the StateRAMP website. | Governance | |
Get Started With GovRAMP – Government Guide | This guide explains the GovRAMP implementation process for governments. | Government Document | |
GovRAMP Adopted Bylaws | This framework for bylaws was developed by the GovRAMP Steering Committee. As the Board of Directors is formed in late 2020, one of their first actions will be to adopt the bylaws for the organization. | Governance | |
GovRAMP Approvals Committee Charter | This charter outlines the duties and responsibilities of the GovRAMP Approvals Committee and their role in providing approvals for product security packages seeking an Authorized status. | Governance | |
GovRAMP Authorization Annual Assessment Controls Selection Workbook | This comprehensive workbook is designed to support 3PAOs and service providers with Provisional or Authorization in tracking audits and maintaining compliance with GovRAMP requirements. | Assessor Templates | |
GovRAMP CJIS-Aligned Overlay Control and Parameters | Download the GovRAMP CJIS-Aligned Overlay to access a unified framework aligning CJIS Policy 5.9.5 with GovRAMP controls, offering tailored guidance for secure cloud procurement decisions. | ||
GovRAMP Overview | This document provides information about the GovRAMP organization, how to become a member, the process for engaging the PMO to complete a security review, requirements for government sponsorship, and how to list products on the Authorized Product List. | Program Document | |
GovRAMP PMO Charter | The PMO Charter defines the objectives, roles, and responsibilities associated with the GovRAMP Program Management Office (PMO). | Governance | |
GovRAMP PMO Fee Schedule | This document provides an updated GovRAMP Program Management Fee Schedule, effective January 1, 2025. | Program Document | |
GovRAMP Provider Sponsor Requirements | This document outlines the process (including government sponsorship requirements) for a vendor’s offering to be listed as GovRAMP Authorized on GovRAMP’s Authorized Product List (APL). | Provider Document | |
GovRAMP Steering Committee Charter | The purpose of this charter is to define the objectives, membership, decision making, meeting schedule, and roles and responsibilities associated with the GovRAMP Steering Committee. | Governance | |
Incident Communications Procedures | This document describes the process for GovRAMP stakeholders to use when reporting information concerning information system security incidents or suspected information system security incidents. | Continuous Monitoring |