
Templates and Resources
StateRAMP’s security templates are developed based on policies adopted by the Board of Directors and recommended by the Steering Committee and Standards & Technical Committee. Find the templates and resources you need on this page.
Announcing StateRAMP's New Rev. 5 Baselines
In May, the StateRAMP Board of Directors adopted the Standards & Technical Committee’s recommended baseline controls that incorporate NIST 800-53 Rev.5 into StateRAMP’s security requirements.
Security Policies
Baseline Requirements
Ready Requirements
Continuous Monitoring
Sample Policies & Procedures
StateRAMP verification relies on independent audits that are conducted by Third Party Assessing Organizations (3PAOs). StateRAMP 3PAOs will use the following templates to report audit findings.
StateRAMP Readiness Assessment Report (RAR) Template
StateRAMP Security Assessment Report (SAR) Template
StateRAMP Security Assessment Plan (SAP) Template
StateRAMP Inventory Workbook Template
Providers will need to complete their StateRAMP System Security Plan (SSP), SSP Attachments and have policies and procedures in order before engaging a Third-Party Assessment Organization (3PAO) for an audit.
System Security Plan (SSP) Template
Plan of Action and Milestones (POAM) Template
Continuous Monthly Executive Summary Template
StateRAMP SSP Attachments
Configuration Management Plan (CMP) Template
Incident Response Plan (IRP) Template
Information System Continuous Monitoring (ISCM) Plan
StateRAMP has worked with the Program Management Office (PMO) to develop sample policy and procedure templates to serve as a resource for providers.
AC – Access Control Policy Template
AC – Access Control Procedure Template
AT – Awareness & Training Policy Template
AT – Awareness & Training Procedure Template
AU – Audit & Accountability Policy Template
AU – Audit & Accountability Procedure Template
CA – Security Assessment and Authorization Policy Template
CA – Security Assessment and Authorization Procedure Template
CM – Configuration Management Policy Template
CM – Configuration Management Procedure Template
CP – Contingency Planning Policy Template
CP – Contingency Planning Procedure Template
IA – Identification & Authentication Policy Template
IA – Identification & Authentication Procedure Template
IR – Incident Response Policy Template
IR – Incident Response Procedure Template
MA – Maintenance Policy Template
MA – Maintenance Procedure Template
MP – Media Protection Policy Template
MP – Media Protection Procedure Template
PE – Physical & Environmental Policy Template
PE – Physical & Environmental Procedure Template
PL – Planning Policy Template
PL – Planning Procedure Template
PS – Personnel Policy Template
PS – Personnel Procedure Template
RA – Risk Assessment Policy Template
RA – Risk Assessment Procedure Template
SA – System & Services Acquisition Policy Template
SA – System & Services Acquisition Procedure Template
SC – System & Communications Protection Policy Template
SC – System & Communications Protection Procedure Template
SI – System & Information Integrity Policy Template
SI – System & Information Integrity Procedure Template
Authorized Product List
The first Authorized Product List (APL) includes a listing of Subscriber Members who are actively pursuing third party verification for their offerings. Follow the steps below to be listed on the Authorized Product List.
Find a StateRAMP 3PAO
Assessors play an important role in conducting independent security audits.
Government Sponsors
A government sponsor is required for providers wishing to submit a request for authorization.
Submit a Review Request
Do you want your products included on the StateRAMP Authorized Product List? Submit a Security Review Request to begin the process.
Connect with the
StateRAMP PMO
StateRAMP is proud to partner with Knowledge Services to serve as the PMO.
Receive StateRAMP Updates
Interested in StateRAMP? Sign up below to receive StateRAMP Updates.