20x Moderate - Phase Two Pilot
The standard for federal cloud security designed to be Continuously Monitored, ensuring that security posture is maintained in real-time rather than just at the point of audit.
Geared toward applications that handle data not strictly "public" but not "critically sensitive," where a breach would have serious adverse effects.
Offers a faster route to authorization than traditional processes while ensuring robust monitoring and protection for moderate-risk data.
⌘KControls
See All (237)ADS-01
PassProviders MUST publicly share up-to-date information about the cloud service offering in both human-readable and machine-readable formats, including at least:
• Direct link to the FedRAMP Marketplace for the offering
• Service Model
• Deployment Model
• Business Category
• UEI Number
• Contact Information
• Overall Service Description
• Detailed list of specific services and their impact levels (see FRR-ADS-03)
• Summary of customer responsibilities and secure configuration guidance
• Process for accessing information in the trust center (if applicable)
• Availability status and recent disruptions for the trust center (if applicable)
• Customer support information for the trust center (if applicable)
ADS-02
PassProviders MUST use automation to ensure information remains consistent between human-readable and machine-readable formats when authorization data is provided in both formats; Providers SHOULD generate human-readable and machine-readable data from the same source at the same time OR generate human-readable formats directly from machine-readable data.
ADS-03
PassProviders MUST share a detailed list of specific services and their impact levels that are included in the cloud service offering using clear feature or service names that align with standard public marketing materials; this list MUST be complete enough for a potential customer to determine which services are and are not included in the FedRAMP authorization without requesting access to underlying authorization data.