SS-26-003 Cloud Service Authorization and Monitoring 

Issue Date: 10/01/2026

PURPOSE

This standard establishes minimum requirements for validating, authorizing, and continuously monitoring third-party cloud services, including Infrastructure as a Service (IaaS), Software as a Service (SaaS), and Platform as a Service (PaaS). It uses a risk-based approach that considers data classification, security categorization, and risk determination and defines requirements for GovRAMP verification and authorization, interim authorization, continuous monitoring, provider responsibilities, and agency oversight.

This standard applies only to third-party cloud services used by the State of Georgia. It does not apply to systems or solutions installed, hosted, and operated within State facilities or data centers. It also does not apply to vendors that use cloud services solely for their internal business operations when those services are not used to process, store, transmit, or otherwise handle State data on behalf of the State.

SCOPE and AUTHORITY

O.C.G.A 50-25-4(a)(8) – State Government, Georgia Technology, General Powers

O.C.G.A 50-25-4(a)(9) – State Government, Georgia Technology, General Powers

O.C.G.A 50-25-4(a)(20) - State Government, Georgia Technology, General Powers

O.C.G.A. 50-25-4(a)(27) – State Government, Georgia Technology, General Powers

O.C.G.A 50-25-4(a)(28) State Government, Georgia Technology General Powers

PS-08-005 Enterprise Information Security Policy 

TERMS AND DEFINITIONS

Agency - every state department, agency, board, bureau, commission, and authority but shall not include any agency within the judicial or legislative branch of state government, the Georgia Department of Defense, departments headed by elected constitutional officers of the state, or the University System of Georgia and shall also not include any authority statutorily required to effectuate the provisions of Part 4 of Article 9 of Title 11. 

GovRAMP – standardized approach to security assessment, authorization, and continuous monitoring of cloud services used by state and local governments. GovRAMP’s security verification model is based on NIST 800-53 Rev. 5. 

GovRAMP Security Snapshot Score (GSSS) - preliminary assessment score indicating a cloud service provider’s current security posture prior to full authorization.

GovRAMP Progressing Snapshot Program (PSP) - program that allows cloud service providers to demonstrate progress toward full GovRAMP authorization while operating under defined interim conditions.

GovRAMP Verified Status – status assigned by GovRAMP to a cloud service product following completion of the applicable GovRAMP validation or authorization process. Verified statuses include Core, Ready, Provisionally Authorized, and Authorized, as applicable to the product’s impact level and GovRAMP requirements.  

GovRAMP Reciprocity Process –established process through which an eligible authorization or security assessment from another recognized authorization framework is reviewed for recognition under the GovRAMP program.

FedRAMP Authorization (ATO / P-ATO) - formal authorization issued by a federal agency or the Joint Authorization Board indicating that a cloud service provider meets FedRAMP security requirements.

Authorization Scope (System Boundary) - defined components and environments included within a cloud service provider’s authorization.

Authorization in Good Standing - status indicating that a provider maintains authorization without suspension, revocation, or significant unresolved deficiencies.

Third-Party Cloud Services/Provider - any person or entity that uses a cloud service to process, store, transmit, analyze or is otherwise permitted access to state-owned information through its provision of services to a State agency. This includes all cloud-based technologies (i.e.):

  • Software as a Service (SaaS) providers - companies that provide hosted application services.
  • Platform as a Service (PaaS) providers – companies that provide hosted application development or deployment services.
  • Infrastructure as a Service (IaaS) providers - companies that provide hosted data storage or processing services.

STANDARD

Agencies shall use GovRAMP as the primary framework for authorization and continuous monitoring of third-party cloud services aligned with NIST SP 800-53 Rev. 5.

Security Categorization and Authorization Requirements

Agencies shall determine security categorization and applicable GovRAMP verification and authorization requirements in accordance with PS-08-012 (Data and Asset Categorization), SS-08-014 (Data Categorization – Impact Level), SS-08-041 (Risk Management Framework), and applicable NIST guidance. Data classification shall be used as an input to the categorization process.

The table below establishes the minimum GovRAMP verification and authorization requirements for cloud services and do not replace an agency’s responsibility for security categorization, system authorization, or risk management.

Typical Data ClassificationMinimum GovRAMP Requirement
PublicSecurity Snapshot Score (GSSS) validation prior to contract award
InternalCore (or achieved within 12 months of contract award)
ConfidentialReady (or achieved within 18 months of contract award)
RestrictedAuthorized (or achieved within 24 months of contract award)

Agencies shall require higher authorization levels, additional controls, or enhanced monitoring when warranted by risk, mission impact, or regulatory requirements.

Third-Party Cloud Services

Agencies shall ensure that third-party cloud services used to process, store, transmit, or otherwise handle State data meet applicable GovRAMP requirements, regardless of whether the cloud service is operated by the contracted vendor or by another cloud service provider used by the vendor.

Prior to contract award or service use, agencies shall validate the cloud service's current GovRAMP standing and determine whether the service meets the applicable GovRAMP requirement or is eligible for an approved interim authorization.

Where a cloud service has not achieved the applicable minimum GovRAMP requirement and is permitted to proceed under an approved interim authorization, the interim authorization shall be approved prior to service use.

Agencies shall determine whether the cloud service is within the applicable authorization scope or system boundary and shall apply the applicable GovRAMP requirements based on the data and services handled by the cloud service.

Authorization Validation and Approval

Authorization determinations shall be reviewed and approved prior to contract award or service use.

Authorization decisions shall identify the applicable cloud service, data classification, security categorization, GovRAMP verification or authorization requirement, current GovRAMP status, authorization scope, and any conditions or limitations applicable to the State's use.

Agencies shall ensure applicable GovRAMP verification and authorization requirements are addressed through procurement, security review, and approval processes appropriate to the procurement method being used.

Agencies shall validate that the GovRAMP verification or authorization applies to the specific cloud service offering and authorization scope or system boundary proposed for or in use by the State.

GovRAMP or other authorization status shall not satisfy the applicable requirement when the authorization scope does not include the cloud service offering or system boundary used by the State.

FedRAMP Reciprocity Through GovRAMP

Agencies shall use the GovRAMP recognized reciprocity process when relying on an eligible FedRAMP authorization to satisfy an applicable GovRAMP requirement.

An eligible FedRAMP authorization may be recognized only where:

  • The FedRAMP authorization is active and in good standing.
  • The authorization scope aligns with the service offering and system boundary in use.
  • GovRAMP recognizes the authorization through an established reciprocity process. 
  • Sufficient documentation is available to support agency risk decisions and ongoing oversight.

Agencies shall validate that the authorization and resulting GovRAMP status and authorization scope remain applicable to the cloud service offering and the State’s intended use.

Agencies shall not accept:

  • FedRAMP Ready designations
  • FedRAMP In Process designations
  • Authorization pathways not recognized through the GovRAMP reciprocity process
  • Unsupported vendor assertions of FedRAMP alignment or equivalency without verifiable authorization and supporting documentation

Agencies may use an approved equivalent authorization framework to satisfy an applicable GovRAMP requirement when the framework and applicable authorization are approved or recognized through an established GovRAMP reciprocity or equivalency process.

Contractual Requirements 

Agencies shall ensure that solicitations, procurement documents, contracts, renewals, and amendments include requirements necessary to support authorization, monitoring, risk management, compliance, and other applicable requirements established by this Standard.

Agencies shall ensure that contracts include requirements for providers to support authorization validation, ongoing monitoring, risk management, and compliance activities applicable to the cloud service, including access to security documentation and monitoring information necessary to support those activities.

Agencies shall ensure that contracts include requirements for providers to notify the applicable agency of material changes to GovRAMP status, authorization scope, or conditions that may affect the State’s authorization decision.

Interim Authorization 

Agencies may use an interim authorization when a cloud service offered by a third-party vendor has not achieved the applicable GovRAMP verification or authorization requirement. 

Interim authorizations shall:

  • Document the cloud service’s current GovRAMP status
  • Identify the applicable GovRAMP verification or authorization requirement and transition timeframe
  • Document the risk associated with use of the service during the transition period
  • Identify required remediation or milestones toward the applicable GovRAMP status
  • Identify applicable compensating controls
  • Establish the conditions and duration of the interim authorization

Agencies utilizing interim authorization shall review provider status, monitor progress toward the applicable GovRAMP verification or authorization requirement, and reassess risk throughout the interim authorization period. 

The interim authorization period shall align with the applicable transition timeframe established in the Security Categorization and Authorization Requirements section.

Agencies may use the GovRAMP Progressing Snapshot Program (PSP) or another GovRAMP recognized progression mechanism to support an approved interim authorization, when applicable.

Interim authorization does not satisfy or waive the final GovRAMP authorization requirement applicable to the cloud service used by the third-party vendor.

Change in Information Sensitivity 

Agencies shall ensure that information processed by a cloud service does not exceed the approved data classification, security categorization, or protection level.

Where a cloud service will process information requiring a higher classification, security categorization, or protection level than originally approved, agencies shall reassess applicable risk and authorization requirements prior to processing such information.

The reassessment shall determine whether a higher GovRAMP status, additional security controls, enhanced monitoring, or other risk-management measures are required before the higher-sensitivity information is processed.

Continuous Monitoring

Agencies shall ensure providers support continuous monitoring and provide access to security artifacts necessary to support ongoing authorization, oversight, and risk management activities.

Agencies shall maintain ongoing visibility into provider authorization status, remediation activities, and associated risk throughout the service lifecycle.

Monitoring access shall be commensurate with data classification, security categorization, and risk determination.

The security documentation and monitoring information required from providers shall be commensurate with the applicable data classification, security categorization, authorization status, and risk determination.

Authorization Maintenance

Agencies shall maintain the applicable authorization decision throughout the service lifecycle, document material changes to authorization status or scope, and verify that the applicable GovRAMP verification or authorization remains active, applicable to the service in use, and within the approved authorization scope.

Agencies shall document material changes to authorization status or scope that may affect the authorization decision.

Agencies shall document the termination or expiration of the authorization when the cloud service is no longer approved for State use.

Documentation and Record Keeping

Agencies shall obtain and maintain documentation necessary to support authorization decisions, validation activities, monitoring activities, exceptions, and risk acceptance decisions.

Documentation shall be maintained throughout the service lifecycle and shall be sufficient to demonstrate the basis for the authorization decision, applicable GovRAMP status, monitoring activities, material authorization changes, and approved exceptions or risk acceptance decisions, consistent with applicable contractual, legal, and confidentiality requirements.

RELATED ENTERPRISE POLICIES, STANDARDS AND GUIDELINES

Data and Asset Categorization (PS-08-012)

Data Categorization - Impact Level (SS-08-014) 

Risk Management Framework (SS-08-041) 

Independent Security Assessments (SS-08-042) 

System Security Plans (SS-08-028) 

Third-Party Security Requirements (SS-08-013) 

Third Party Service Provider Verification and Screening (SS-24-001) 

Outsourced IT Services and Third-Party Interconnections (SS-08-044) 

Data Location and Access (SS-15-002) 

Information Security Controls (SS-17-001) 

Cryptographic Controls (SS-08-040) 

Authorization and Access Management (SS-08-010) 

Terms and Conditions for Cloud Services (SM-14-010)

Enterprise Managed Services (EMS) (SM-15-009)

REFERENCES

NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (current published version)

GovRAMP 

GovRAMP Authorized Product List

GovRAMP Baseline Controls Matrix and Guidance

FedRAMP Marketplace

FedRAMP Authorization 

NIST SP 800-37, Risk Management Framework for Information Systems and Organizations

FIPS Publication 199 Standards for Security Categorization of Federal Information and Information Systems

NIST SP 800-60 Guide for Mapping Types of Information and Information Systems to Security Categories