FedRAMP FedRAMP Authorization Process & Documentation 1 — Questions and Answers
Question 1: Which document serves as the primary artifact that describes a cloud system's security controls and how they are implemented for FedRAMP authorization?
- System Security Plan (SSP) (Correct answer)
- Plan of Action and Milestones (POA&M)
- Security Assessment Report (SAR)
- Authorization to Operate (ATO)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the central FedRAMP document that describes all security controls and their implementation for a cloud system.
Question 2: What is the primary purpose of a Plan of Action and Milestones (POA&M) in the FedRAMP process?
- To document and track remediation of identified security weaknesses (Correct answer)
- To authorize a system to operate in a federal environment
- To describe the cloud service provider's business continuity plan
- To list all authorized users of the cloud system
Correct answer: To document and track remediation of identified security weaknesses
A POA&M tracks identified security weaknesses, their remediation plans, and milestone dates for resolution.
Question 3: In the FedRAMP authorization process, who issues the final Authorization to Operate (ATO)?
- An Authorizing Official (AO) at the sponsoring federal agency (Correct answer)
- The FedRAMP Program Management Office (PMO)
- A Third-Party Assessment Organization (3PAO)
- The cloud service provider's CISO
Correct answer: An Authorizing Official (AO) at the sponsoring federal agency
The Authorizing Official (AO) at the sponsoring federal agency is responsible for issuing the final ATO decision.
Question 4: What does the FedRAMP 'Ready' designation indicate about a cloud service offering?
- The CSP has demonstrated basic security capabilities and is ready to pursue full authorization (Correct answer)
- The CSP has received a full Authorization to Operate
- The CSP has passed all 3PAO security tests
- The CSP is approved for use across all federal agencies
Correct answer: The CSP has demonstrated basic security capabilities and is ready to pursue full authorization
FedRAMP Ready indicates the CSP has met baseline security requirements and is positioned to pursue full authorization.
Question 5: Which FedRAMP authorization path allows a Cloud Service Provider to pursue authorization sponsored directly by the FedRAMP PMO rather than a single agency?
- FedRAMP Agency Authorization
- FedRAMP JAB Provisional Authorization (Correct answer)
- FedRAMP Tailored Authorization
- FedRAMP Ready Designation
Correct answer: FedRAMP JAB Provisional Authorization
The Joint Authorization Board (JAB) Provisional ATO (P-ATO) is sponsored by the FedRAMP PMO and represents the top-tier authorization path.
Question 6: What is the maximum acceptable risk level for a cloud system to receive a FedRAMP High baseline authorization?
- No unmitigated critical or high risks; moderate risks must be accepted (Correct answer)
- No unmitigated risks of any kind are permitted
- Up to 10 high risks and unlimited moderate risks
- High risks are acceptable if offset by compensating controls
Correct answer: No unmitigated critical or high risks; moderate risks must be accepted
FedRAMP High authorizations require that critical and high residual risks be resolved or accepted by the AO, with no unmitigated critical findings.
Which document serves as the primary artifact that describes a cloud system's security controls and how they are implemented for FedRAMP authorization?