FedRAMP process
RMF | FedRAMP | ARTIFACTS | RESPONSIBILITY |
N/A | Initiate | SA&A Package | Agency(Review Package) |
N/A | Apply | Request Form | Agency or Cloud Service Provider(CSP) |
Categorization | Implement | FIPS199, RAR, PTA, PIA, SORNand E-Authentication | Third Party Assessor Organization(3PAO) |
Control Selection | Implement | Security Control baseline | Third Party Assessor Organization(3PAO) |
Implementation | Document | SSP, CMP, CP, and CP test | Cloud Service Provider(CSP) |
Assessment | Assess | SAP, ST&E, and SAR | Third Party Assessor Organization(3PAO) |
Authorization | Authorize | POAM and ATO | Joint Authorization Board(JAB) or Agency |
Continuous Monitoring | Monitor | POAM, SSP, and SAR | JAB(review package), Agency(review package) and CSP (Provide package) |
N/A | Report | N/A | Agency |