FedRAMP FedRAMP Authorization Process & Documentation 2 — Questions and Answers
Question 1: Which NIST publication provides the core security control catalog used as the foundation for FedRAMP security requirements?
- NIST SP 800-53 (Correct answer)
- NIST SP 800-37
- NIST SP 800-171
- NIST SP 800-61
Correct answer: NIST SP 800-53
NIST SP 800-53 (Security and Privacy Controls for Information Systems) is the foundational control catalog for FedRAMP.
Question 2: What is the FedRAMP 'Marketplace' and what is its primary function?
- A public directory of authorized FedRAMP cloud services available for agency use (Correct answer)
- A procurement platform for purchasing cloud services
- A testing environment for 3PAO assessments
- A repository for storing SSPs and SARs
Correct answer: A public directory of authorized FedRAMP cloud services available for agency use
The FedRAMP Marketplace is a publicly searchable directory listing all authorized cloud services, their status, and authorization details.
Question 3: How long is a FedRAMP authorization valid before it must be re-authorized or reaffirmed?
- 3 years
- 1 year
- 5 years
- Indefinitely, as long as continuous monitoring requirements are met (Correct answer)
Correct answer: Indefinitely, as long as continuous monitoring requirements are met
FedRAMP authorizations do not expire on a fixed schedule; they remain valid as long as the CSP meets continuous monitoring and reporting requirements.
Question 4: What must a Cloud Service Provider submit to initiate the FedRAMP Agency Authorization process?
- A completed SSP, SAP, and evidence of a federal agency sponsor (Correct answer)
- Only a completed Security Assessment Report (SAR)
- A FedRAMP Ready designation from the PMO
- A letter of intent signed by a 3PAO
Correct answer: A completed SSP, SAP, and evidence of a federal agency sponsor
To initiate agency authorization, a CSP needs a completed SSP, a Security Assessment Plan, and a federal agency willing to sponsor and fund the authorization.
Question 5: In FedRAMP documentation, what is the purpose of the Control Implementation Summary (CIS)?
- To provide a high-level matrix of which controls are implemented by the CSP vs. the customer (Correct answer)
- To summarize the findings from a 3PAO security assessment
- To track the status of POA&M remediation items
- To list all personnel with system access
Correct answer: To provide a high-level matrix of which controls are implemented by the CSP vs. the customer
The CIS is a matrix that shows the implementation status and responsibility (CSP, customer, or shared) for each FedRAMP security control.
Question 6: What distinguishes a FedRAMP 'In Process' designation from a FedRAMP 'Authorized' designation?
- 'In Process' means the CSP is actively working toward authorization but has not yet received an ATO (Correct answer)
- In Process means the ATO has been granted but is under review
- 'Authorized' means the CSP has passed the readiness assessment only
- 'In Process' applies only to JAB authorizations
Correct answer: 'In Process' means the CSP is actively working toward authorization but has not yet received an ATO
FedRAMP 'In Process' means the CSP is actively pursuing authorization with a sponsoring agency or the JAB but has not yet received an ATO.
Which NIST publication provides the core security control catalog used as the foundation for FedRAMP security requirements?