Cloud Service Authorization and Monitoring (PS-26-001)
Topics:
PS-26-001 Cloud Service Authorization and Monitoring
Issue Date: 10/01/2026
PURPOSE
This policy establishes enterprise requirements for authorizing and managing the ongoing risk of third-party cloud services that process, store, or transmit State data. It provides a consistent, risk-based approach based on data classification, security categorization, and risk determination, in alignment with GovRAMP and other approved equivalent authorization frameworks. This policy applies to all third-party cloud services used by State agencies to process, store, or transmit State data.
SCOPE and AUTHORITY
O.C.G.A 50-25-4(a)(8) – State Government, Georgia Technology, General Powers
O.C.G.A 50-25-4(a)(9) – State Government, Georgia Technology, General Powers
O.C.G.A 50-25-4(a)(20) - State Government, Georgia Technology, General Powers
O.C.G.A. 50-25-4(a)(27) – State Government, Georgia Technology, General Powers
O.C.G.A 50-25-4(a)(28) State Government, Georgia Technology General Powers
PS-08-005 Enterprise Information Security Policy
TERMS AND DEFINITIONS
Agency - every state department, agency, board, bureau, commission, and authority but shall not include any agency within the judicial or legislative branch of state government, the Georgia Department of Defense, departments headed by elected constitutional officers of the state, or the University System of Georgia and shall also not include any authority statutorily required to effectuate the provisions of Part 4 of Article 9 of Title 11.
GovRAMP - standardized approach to security assessment, authorization, and continuous monitoring of cloud services used by state and local governments.
Third-party cloud service - any person or entity that maintains, processes, or otherwise is permitted access to state-owned information through its provision of services. This includes all cloud-based technologies (i.e.):
- Software as a Service (SaaS) providers - companies that provide hosted application services.
- Platform as a Service (PaaS) providers – companies that provide hosted application development or deployment services.
- Infrastructure as a Service (IaaS) providers - companies that provide hosted data storage or processing services.
POLICY
Agencies shall use GovRAMP as the primary framework for the authorization and continuous monitoring of third-party cloud services that process, store, or transmit State data.
Agencies shall ensure that cloud services handling State data are appropriately authorized, continuously monitored, and managed throughout their lifecycle in accordance with State security, risk, procurement, and governance requirements.
Georgia Technology Authority’s Office of Information Security (GTA OIS) shall provide enterprise level oversight of third-party cloud service authorization and monitoring, including visibility into authorization status, risks, and compliance across agencies, and may perform validation, monitoring, and reporting activities to support enterprise visibility, risk reporting, and consistent implementation.
RELATED ENTERPRISE POLICIES, STANDARDS AND GUIDELINES
- Enterprise Information Security Policy (PS-08-005)
- Cloud Provisioning Policy (PS-22-001)
- Data and Asset Categorization (PS-08-012)
- Information Security Risk Management (PS-08-031)
- Security Controls Review and Assessments (PS-08-029.02)
- Third-Party Access (PS-08-011)
- Information Security Controls (PS-17-001)
- Use of Cryptography (PS-08-024)
REFERENCES
- NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version)
- GovRAMP
- GovRAMP Authorized Product List
- FedRAMP Marketplace
- FedRAMP Authorization
- NIST SP 800-37 Rev. 2
- FIPS 199
- FIPS 200