Third-Party Cloud Service Risk Authorization & Management – Agency Implementation Guideline (GS-26-001)
Topics:
GS-26-001 Third-Party Cloud Service Risk Authorization & Management – Agency Implementation Guideline
Issue Date: 10/01/2026
PURPOSE
The purpose of this document is to provide practical guidance to State agencies for implementing the State’s requirements for authorizing and managing the ongoing risk of third-party cloud services. It outlines recommended practices that agencies can apply throughout the cloud service lifecycle.
Agencies should tailor this guidance, as appropriate, based on the cloud service and its intended use, the State data involved, security categorization, mission impact, risk, procurement method, and applicable legal, regulatory, contractual, and agency-specific requirements. When this guidance references a requirement established by an applicable State policy or standard, the policy or standard takes precedence.
SCOPE and AUTHORITY
O.C.G.A 50-25-4(a)(8), State Government, Georgia Technology, General Powers
O.C.G.A 50-25-4(a)(20), State Government, Georgia Technology, General Powers
PM-04-001 Information Technology Policies, Standards and Guidelines
PS-08-005 – Enterprise Information Security Policy
TERMS AND DEFINITIONS
GovRAMP – Standardized approach to security assessment, authorization, and continuous monitoring of cloud services used by state and local governments.
Authorization Scope (System Boundary) – Defined components and environments included within a cloud service provider's authorization.
GovRAMP Security Snapshot Score (GSSS) – Preliminary assessment score indicating a cloud service provider's current security posture prior to full authorization.
GovRAMP Progressing Snapshot Program (PSP) – Program that allows cloud service providers to demonstrate progress toward full GovRAMP authorization while operating under defined interim conditions.
GovRAMP Verified Status – Status assigned by GovRAMP to a cloud service product following completion of the applicable GovRAMP validation or authorization process. Verified statuses include Core, Ready, Provisionally Authorized, and Authorized, as applicable to the product's impact level and GovRAMP requirements.
GovRAMP Reciprocity Process – The GovRAMP process through which an eligible authorization or security assessment from another recognized authorization framework may be reviewed for recognition. Providers work directly with GovRAMP to determine the applicable reciprocity pathway and activities.
Interim Authorization – The time limited authorization mechanism established by SS-26-003 for use of a cloud service that has not achieved the applicable GovRAMP verification or authorization requirement. Interim authorization does not satisfy or waive the final GovRAMP requirement. SS-26-003 establishes the required elements and conditions for use of an interim authorization.
Third-Party Cloud Services/Provider – Any person or entity that uses a cloud service to process, store, transmit, analyze, or is otherwise permitted access to State-owned information through its provision of services to a State agency. This includes Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS) providers.
GUIDELINES
1. Agency Implementation Approach
GTA recommends that agencies integrate GovRAMP into their existing security, risk-management, procurement, contracting, and system-authorization processes rather than treating GovRAMP as a separate vendor-compliance activity.
Agencies can use the following lifecycle to apply State GovRAMP requirements from initial cloud service review through ongoing monitoring, renewal, or exit:
| Phase | Agency Activity | Outcome |
|---|---|---|
| Understand the Service |
| Define the cloud service, intended use, information handled, and key stakeholders |
| Determine the Requirement |
| Determine State data classification and security categorization |
| Establish the applicable State minimum GovRAMP requirement and identify additional security considerations | |
| Evaluate the Provider |
| Confirm the exact offering, current GovRAMP status, and Authorization Scope (System Boundary) |
| Determine whether the provider meets the requirement or whether an applicable interim authorization pathway is needed | |
| Acquire and Authorize |
| Carry the approved requirements and provider commitments through procurement and contracting |
| Document the agency authorization decision, conditions for use, and agency-managed responsibilities | |
| Manage Ongoing Risk |
| Review provider status, findings, milestones, material changes, agency controls, and risk |
| Reevaluate the authorization when material conditions or risk change | |
| Continue or Exit |
| Determine whether to renew, remediate, replace, transition, or discontinue the service |
GovRAMP provides reusable security assurance regarding the cloud service provider. The agency remains responsible for decisions about its specific use of the service, State data, agency-managed controls, and risk.
Recommended Practice: Start the cloud review early enough that the applicable security requirement is known before vendor selection, contract execution, or production use.
The Recommended Roles and RACI section provides a practical model for assigning and coordinating responsibilities across this lifecycle.
2. Recommended Roles and RACI
The following RACI provides a recommended approach for coordinating responsibilities throughout the third-party cloud service lifecycle.
Agencies should adapt the matrix, as appropriate, to their organizational structure, procurement model, delegated authorities, and existing governance processes. The matrix does not replace responsibilities established in applicable State policies, standards, procurement requirements, contracts, or agency governance.
RACI Terms
- R – Responsible: Performs or coordinates the activity
- A – Accountable: Owns the decision or outcome
- C – Consulted: Provides input or subject-matter expertise
- I – Informed: Receives relevant information or status
Recommended Agency RACI
| Lifecycle Activity | Business / System Owner | Data Owner | Security / ISO | Procurement | Contracts / Legal | Authorizing Official | GTA* | Cloud Provider |
|---|---|---|---|---|---|---|---|---|
| Identify business need and intended use | A/R | C | C | I | I | I | I | C |
| Identify cloud service and service model | R | I | A/R | C | I | I | C | C |
| Identify information types | R | A/R | C | I | I | I | I | I |
| Determine State data classification | C | A/R | C | I | I | I | I | I |
| Determine security categorization / impact | C | C | A/R | I | I | C | C | I |
| Determine applicable State GovRAMP requirement | I | C | A/R | I | I | C | C | I |
| Determine enterprise vs. agency validation path | I | I | R | C | I | I | A/R* | I |
| Validate provider status and Authorization Scope (System Boundary) | I | I | A/R | C | I | I | R* | C |
| Determine whether interim authorization is appropriate | C | C | R | I | C | A | C | C |
| Define interim conditions, milestones, and monitoring needs | C | I | A/R | C | C | C | C | R |
| Carry security requirements into procurement | C | I | C | A/R | C | I | C | C |
| Evaluate vendor GovRAMP information | I | I | R | A/R | I | I | C | C |
| Incorporate applicable requirements into contract | I | I | C | C | A/R | I | C | C |
| Implement agency-managed controls | A/R | C | C | I | I | I | I | C |
| Provide provider-managed security evidence | I | I | C | I | I | I | I | A/R |
| Make agency authorization decision | C | C | R | I | I | A | C | I |
| Maintain authorization and risk information in Enterprise GRC | C | I | A/R | I | I | C | C | I |
| Perform ongoing security monitoring | C | I | A/R | I | C | I | C | R |
| Track contract milestones and commitments | I | I | C | C | A/R | I | I | R |
| Review material provider or service changes | C | C | A/R | I | C | C | C | R |
| Reassess security risk when conditions change | C | C | A/R | I | C | C | C | I |
| Review at renewal, extension, or major modification | A/R | C | R | R | R | C | C | C |
| Determine continued authorization | C | C | R | I | I | A | C | I |
| Plan replacement, transition, or exit when needed | A/R | C | C | C | C | I | I | C |
* GTA involvement depends on the procurement path. For State enterprise IT procurements, GTA performs the applicable enterprise GovRAMP validation and approval activities. For agency or non-enterprise procurements, the agency performs the applicable validation and risk review in accordance with State requirements.
How to Use the RACI: The RACI is intended to help agencies answer four practical questions:
- Who performs or coordinates the activity?
- Who owns the decision or outcome?
- Who should provide input?
- Who should receive relevant information or status?
Agencies may adapt role assignments when their governance model assigns responsibilities differently, provided applicable State and agency requirements continue to be met.
Key Role Boundaries:
- Business / System Owner – Owns the business need, intended use, implementation, and operational use of the service.
- Data Owner – Determines or approves the applicable State data classification.
- Security / ISO – Performs or coordinates security review, security categorization, GovRAMP requirement determination, provider validation, risk assessment, monitoring, and reassessment.
- Procurement – Carries approved requirements into solicitation, vendor evaluation, and award activities.
- Contracts / Legal – Incorporates applicable requirements and provider commitments into the agreement and supports contract administration.
- Authorizing Official – Makes or approves the agency authorization and risk decision in accordance with applicable agency and State processes.
- GTA – Performs applicable enterprise validation, approval, oversight, and guidance activities based on the procurement path and State requirements.
- Cloud Provider – Provides accurate service, authorization, boundary, security, monitoring, remediation, and milestone information and performs applicable provider responsibilities.
3. Determine Whether the Cloud Service Is in Scope
Agencies should first determine whether a proposed service includes a third-party cloud component subject to PS-26-001 and SS-26-003.
Useful questions include:
- Is the service hosted outside a State-controlled environment?
- Will a third-party process, store, transmit, analyze, or otherwise handle State data?
- Is the service SaaS, PaaS, IaaS, or another hosted service?
- Does a contractor use another cloud provider to handle State data?
- Does the solution include cloud-hosted AI or another cloud-enabled capability?
PS-26-001 and SS-26-003 generally do not apply when a system is hosted and operated within State facilities with no third-party cloud service involved, or when a vendor uses cloud services only for its internal business operations and does not handle State data on behalf of the State.
Recommended Practice: Focus on how the service is delivered and how State data is handled, not only on how the product is marketed or labeled.
4. Identify the Service and Intended Use
Before determining the applicable GovRAMP requirement, agencies should understand the specific service and how the agency intends to use it.
Useful information includes:
- Provider
- Product or service
- Business purpose
- Business or system owner
- Intended users
- State data involved
- Systems and integrations
- Hosting or deployment model
- Material cloud dependencies or subcontractors
- Applicable legal, regulatory, privacy, records, and contractual requirements
Practical Question: What exactly is the agency authorizing, for what purpose, and with what State data?
Answering this question early helps ensure that provider status is evaluated against the agency's actual use.
5. Classify State Data
Agencies should identify the information the cloud service will process, store, transmit, generate, or otherwise access and classify State data in accordance with PS-26-002 and SS-26-002.
The State data classification levels are: Public, Internal, Confidential, Restricted
The Data Owner, business or system owner, Security, and other knowledgeable personnel may need to work together when determining the appropriate classification.
When different classifications are involved, the highest applicable State data classification should be considered when applying the State minimum GovRAMP requirement established by SS-26-003.
Recommended Practice: Identify the actual information types rather than relying only on broad labels such as PII or sensitive data. Consider information such as:
- Personnel information
- Financial or tax information
- Health information
- Criminal justice information
- Authentication information
- Operational and mission information
- Security information
- Logs and metadata
- Reports and exports
- Derived information and analytics
- AI-generated outputs, when applicable
6. Determine Security Categorization
State data classification and system security categorization are related but separate activities.
Agencies should apply applicable State categorization requirements and consider NIST SP 800-60 and FIPS 199 when determining the potential impact of a loss of confidentiality, integrity, or availability.
The resulting security categorization supports the agency's overall security, risk, and authorization determination.
Key Distinction:
- State data classification identifies the sensitivity and protection needs of State data and establishes the State minimum GovRAMP requirement under SS-26-003.
- Security categorization evaluates the potential impact of a loss of confidentiality, integrity, or availability and supports system risk management and security control decisions.
- Neither should be used as a substitute for the other.
7. Determine the Applicable GovRAMP Requirement
SS-26-003 establishes the State minimum GovRAMP requirements.
For reference:
| State Data Classification | State Minimum GovRAMP Requirement |
|---|---|
| Public | Security Snapshot Score (GSSS) validation prior to contract award |
| Internal | Core, or achievement within 12 months of contract award when an interim authorization is approved |
| Confidential | Ready, or achievement within 18 months of contract award when an interim authorization is approved |
| Restricted | Authorized, or achievement within 24 months of contract award when an interim authorization is approved |
These requirements originate in SS-26-003; this guideline does not establish or modify them.
A lower FIPS 199 or GovRAMP impact determination does not reduce the State minimum established through the applicable State data classification.
Agencies should also consider whether security categorization, mission impact, regulatory requirements, intended use, or other risk indicates a need for:
- Additional security controls
- Enhanced monitoring
- Additional contractual safeguards
- Additional conditions on use
- A higher GovRAMP requirement
Recommended Practice: Record both the State minimum GovRAMP requirement and any additional safeguards identified through the agency risk review.
8. Validate the Provider and Exact Cloud Offering
Agencies should validate the specific cloud offering being considered rather than relying only on the provider's name or general GovRAMP status.
Useful validation information includes:
- Legal provider
- Exact product or service
- Current GovRAMP status
- Applicable GovRAMP Verified Status
- Authorization Scope (System Boundary)
- Hosting or deployment model
- Applicable impact level or baseline
- Relevant conditions or limitations
- Material cloud dependencies
- Applicable FedRAMP information when reciprocity is proposed
Recommended Practice: Validate the product, scope, and State use—not simply the company.
A GovRAMP status held by a provider, affiliate, infrastructure provider, or another product does not necessarily apply to the service the agency intends to use.
9. Determine the Applicable Validation Path
The validation path depends in part on how the service is procured.
For State enterprise IT procurements, GTA performs the applicable enterprise GovRAMP validation and approval activities.
For agency or non-enterprise procurements, the agency performs the applicable validation and risk review in accordance with State requirements.
Regardless of procurement path, the agency remains responsible for its:
- Business need
- State data classification
- Agency risk decision
- Agency-managed controls
- Authorization for agency use
- Ongoing oversight
Recommended Practice: Determine the procurement and validation path early so the agency understands who performs the applicable validation and when it is needed.
10. Determine the Authorization Path
After validating the provider, compare the provider's current status with the applicable State requirement.
There are generally two paths:
- Required status achieved - Continue the agency security and risk review and determine whether the service is appropriate for the intended State use.
- Required status not yet achieved - Determine whether interim authorization is available and appropriate under SS-26-003.
GovRAMP status is an important input to the decision, but it does not by itself authorize agency use of the service.
11. Interim Authorization
SS-26-003 provides for interim authorization when applicable conditions are met.
An interim authorization allows time-limited agency use while the provider progresses toward the applicable GovRAMP requirement, subject to the conditions established in SS-26-003.
When evaluating an interim authorization, agencies should consider:
- Current provider status
- Required final status
- Applicable achievement timeframe
- Risk of use before final status is achieved
- Material security findings or gaps
- Provider remediation
- Measurable milestones
- Compensating controls
- Conditions or limitations on use
- Evidence of progress
- Monitoring and review needs
The interim authorization should provide a defined, time limited path toward the applicable GovRAMP requirement and should not become an indefinite alternative to achieving it.
Interim Authorization Is Not an Exception - An interim authorization is an authorization mechanism provided under SS-26-003.
A policy or standard exception is a separate approval to deviate from an applicable State policy or standard and follows the applicable State exception process.
A simple distinction is:
- Required GovRAMP status - the status the provider is expected to achieve.
- Interim authorization - the agency's time limited authorization while the provider progresses toward that status.
- GovRAMP progression mechanism - a mechanism that may provide evidence of provider progress.
12. GovRAMP Progression
A provider may use the GovRAMP Progressing Snapshot Program (PSP) or another GovRAMP recognized progression mechanism while working toward the applicable required status.
Progression information may help agencies understand:
- Current provider security posture.
- Assessment results.
- Remediation progress.
- Milestone completion.
- Changes in security maturity.
- Whether the provider remains on track to achieve the required status.
Participation in a progression mechanism may support an interim authorization, but it does not itself constitute agency authorization or achievement of the final required GovRAMP status.
13. FedRAMP and GovRAMP Reciprocity
An applicable FedRAMP authorization or federal security assessment may support the GovRAMP reciprocity process.
When this occurs, the agency should ask the provider to work directly with GovRAMP to determine the applicable reciprocity pathway and activities. The agency should validate, as applicable:
- Exact service offering
- Current FedRAMP authorization status
- Authorization Scope (System Boundary)
- Applicability to the State's intended use
- Whether an interim authorization applies while the GovRAMP reciprocity process is completed
GovRAMP can work with the provider to determine the reciprocity activities that apply to the specific offering and authorization.
FedRAMP should not be treated as an automatic substitute for the State's GovRAMP requirement. The provider should work with GovRAMP to complete the applicable reciprocity process, and the agency should confirm that the resulting GovRAMP status and Authorization Scope (System Boundary) support the State's intended use.
14. Incorporate the Requirement into Procurement
Once Security has established the applicable GovRAMP requirement, Procurement can carry that requirement into the acquisition process.
Useful information for Procurement may include:
- Exact cloud service.
- Required GovRAMP status.
- Current provider status.
- Authorization Scope (System Boundary).
- Applicable evidence.
- Interim authorization considerations.
- Achievement timeframe.
- Material security conditions.
The GovRAMP Procurement Guideline provides practical guidance for procurement intake, solicitation development, vendor evaluation, and pre-award activities.
Recommended Practice: Establish the security requirement before the procurement is substantially developed so vendors receive clear and consistent expectations.
15. Incorporate the Requirement into the Contract
Applicable GovRAMP requirements and material provider commitments should be carried into the resulting contract.
Depending on the service, relevant considerations may include:
- Applicable GovRAMP status
- Achievement timeframe
- Milestones
- Security evidence access
- Continuous monitoring information
- Material change notification
- Incident notification and cooperation
- Subcontractors and cloud dependencies
- Shared responsibilities
- Remediation
- Renewal and exit
16. Identify Shared Responsibility
GovRAMP evaluates security controls within the assessed cloud-service boundary. Responsibilities outside that boundary may remain with the agency or another provider.
Agency responsibilities may include:
- Identity and access management
- Privileged access
- Agency controlled configuration
- Logging and monitoring
- Encryption and key management choices
- Integrations
- Agency managed endpoints
- Incident coordination
- Backup and recovery
- Data handling and retention
- Business continuity
Practical Question: What security responsibilities remain with the agency after the provider's cloud service has been verified or authorized?
A shared responsibility matrix or similar documentation can help clarify those responsibilities.
17. Make the Agency Authorization Decision
Before production use, the agency should document its authorization decision in accordance with applicable State requirements.
Useful information includes:
- Cloud service and provider
- Intended use
- Information types
- State data classification
- Security categorization
- Applicable GovRAMP impact information
- State minimum GovRAMP requirement
- Current provider status
- Authorization Scope (System Boundary)
- Agency managed controls
- Shared responsibilities
- Material residual risks
- Conditions or limitations
- Interim authorization information, when applicable
- Monitoring considerations
Authorization and risk information should be maintained through Enterprise GRC or the applicable State designated process, consistent with State requirements and procedures.
Key Principle:
- GovRAMP provides security assurance regarding the provider. The agency remains responsible for determining whether and how the service may be used for its specific mission, systems, and State data.
18. Continuous Monitoring and Ongoing Risk Management
Authorization is not the end of the process.
Consistent with the State's Risk Management Framework (RMF), continuous monitoring supports ongoing risk management by helping agencies identify changes in security posture, control effectiveness, provider status, and other conditions that may affect the authorization decision.
Agencies should use applicable GovRAMP monitoring information together with agency security monitoring, contract oversight, findings management, and risk-management activities.
Areas to consider include:
- Current GovRAMP status
- Authorization Scope (System Boundary)
- Material findings
- POA&M activity
- Vulnerability information
- Remediation progress
- Provider changes
- Agency managed controls
- Interim authorization milestones
- Contract commitments
- Security incidents
- Changes in State use or data
The depth of monitoring should reflect the service, State data classification, security categorization, authorization status, risk, and applicable State RMF practices.
Recommended Practice: Treat continuous monitoring as risk monitoring, not simply document collection. Monitoring should help answer:
Has the risk changed, and does continued use remain appropriate?
19. Reassess When Conditions Change
The authorization should be reassessed when material conditions change and may affect the basis for the original decision.
Examples may include:
- Higher classification State data
- New information types
- Expanded functionality
- Significant new integrations
- Hosting or region changes
- Authorization-scope changes
- New material subcontractors
- Change in GovRAMP status
- Significant security incident
- Significant findings
- Missed interim authorization milestones
- Material change in agency use or mission dependency
The depth of reassessment should be proportionate to the change and associated risk.
20. Review at Renewal, Extension, or Major Change
Renewal and other contract lifecycle events provide natural opportunities to confirm that the service continues to meet State requirements and agency needs.
Questions to consider include:
- Is the provider's GovRAMP status current?
- Does the applicable scope still cover the service being used?
- Have required milestones been completed?
- Are significant findings outstanding?
- Has the State data classification changed?
- Has security categorization changed?
- Has the agency's use changed?
- Have material cloud dependencies changed?
- Do agency managed controls remain appropriate?
- Does the agency continue to authorize the service?
Existing cloud contracts enter the applicable GovRAMP process at renewal, extension, major modification, or new solicitation as established by PS-26-001 and SS-26-003.
If continued use is no longer appropriate, agencies should begin remediation, replacement, migration, non-renewal, or other appropriate action early enough to manage business and security risk.
21. Maintain Appropriate Documentation
Agencies should maintain enough security and risk information to support and explain the cloud authorization throughout the service lifecycle and applicable State Risk Management Framework (RMF) activities.
Useful records may include:
- Cloud service identification
- Intended use
- State data classification
- Security categorization
- GovRAMP impact information
- Required GovRAMP status
- Provider validation
- Authorization Scope (System Boundary)
- Interim authorization information
- Agency authorization decision
- Shared-responsibility information
- Monitoring results
- Material changes
- Risk reassessments
- Procurement and contract information
- Renewal or exit decisions
These records can support applicable RMF activities, including assessment, authorization, continuous monitoring, and risk reassessment throughout the service lifecycle.
Enterprise GRC should be used as the applicable State system of record, consistent with State requirements and procedures.
22. Agency Implementation Checklist
The following provides a simple lifecycle check agencies can use to support implementation.
- Before Procurement or Selection
- Cloud component identified
- Intended use understood
- Business/system owner identified
- State data identified and classified
- Security categorization completed as applicable
- GovRAMP requirement established
- Procurement/validation path identified
- Before Award or Service Use
- Exact provider and product identified
- Current GovRAMP status validated
- Authorization Scope (System Boundary) reviewed
- Applicable reciprocity evaluated
- Interim authorization addressed, when applicable
- Procurement and contract requirements addressed
- Agency managed controls identified
- Authorization decision completed before production use
- During Use
- Provider status monitored
- Applicable findings reviewed
- Interim milestones tracked
- Agency-managed controls monitored
- Material changes assessed
- Security incidents considered
- Risk reassessed when needed
- At Renewal or Material Change
- Current provider status revalidated
- Service scope revalidated
- State data classification reviewed
- Security categorization reviewed as appropriate
- Outstanding milestones and findings considered
- Contract requirements reviewed
- Agency authorization/risk decision reconsidered
- Replacement or exit considered when requirements cannot be met
23. How This Guideline Fits with the GovRAMP Guidance Series
This guideline provides the overall agency implementation framework.
The supporting role-based guidelines provide additional practical direction:
- GovRAMP Security Review and Cloud Authorization Guideline – Security review, categorization, provider validation, authorization, monitoring, and reassessment.
- GovRAMP Procurement Guideline – Procurement intake, solicitation, vendor evaluation, validation coordination, and award considerations.
- GovRAMP Contracting and Contract Administration Guideline – Contract development, provider commitments, monitoring support, milestones, renewal, and exit considerations.
The GovRAMP guidance documents work together across one coordinated agency lifecycle rather than as separate processes:
| Guidance / Lifecycle Stage | Primary Purpose |
|---|---|
| Agency Implementation Framework | Provides the overall lifecycle, decision model, and how the supporting guidance connects |
| Security Review | Determines classification, categorization, applicable GovRAMP requirement, provider status, and authorization path |
| Procurement | Carries the approved requirement into solicitation, evaluation, and award activities |
| Contracting | Incorporates applicable requirements and provider commitments into the agreement |
| Authorization and Use | Documents the agency authorization decision and approved conditions for use |
| Monitoring and Reassessment | Reviews provider status, findings, milestones, changes, agency managed controls, and ongoing risk |
| Renewal or Exit | Determines whether to continue, remediate, replace, transition, renew, or discontinue the service |
RELATED ENTERPRISE POLICIES, STANDARDS AND GUIDELINES
- PS-26-001 – Cloud Service Authorization and Monitoring Policy
- SS-26-003 – Cloud Service Authorization and Monitoring Standard
- PS-26-002 – Enterprise Data Classification & Handling Policy
- SS-26-002 – Enterprise Data Classification & Handling Standard
- PS-08-012 – Data and Asset Categorization
- SS-08-014 – Data Categorization – Impact Level
- SS-08-041 – Risk Management Framework
- SS-08-028 – System Security Plans
- PS-22-001 – Cloud Provisioning Policy
- SS-08-013 – Third-Party Security Requirements
- SS-24-001 – Third Party Service Provider Verification and Screening
- SS-08-044 – Outsourced IT Services and Third-Party Interconnections
- SS-15-002 – Data Location and Access
- SM-14-010 – Terms & Conditions for Cloud Services
- SM-15-009 – Enterprise Managed Services
REFERENCES
- GovRAMP Security Program – Provides information on the GovRAMP security verification and authorization framework, including applicable security statuses and program pathways.
- GovRAMP Program Participants – Provides current public information on cloud service providers and products participating in GovRAMP, including applicable verification and progression status.
- GovRAMP Document Library – Provides current GovRAMP program documentation, templates, security frameworks, continuous monitoring resources, and other implementation materials.
- GovRAMP Progressing Security Snapshot Program – Provides information on the progression pathway available to cloud service providers working toward an applicable GovRAMP Verified Status.
- FedRAMP Marketplace – Provides current public information on cloud service offerings participating in FedRAMP, including applicable federal authorization or certification information.
- NIST Special Publication 800-60 Volumes 1 and 2, Guide for Mapping Types of Information and Information Systems to Security Categories – Provides guidance for identifying information types and establishing provisional security impact levels. NIST SP 800-60 Vol. 1 Rev. 1 ;
NIST SP 800-60 Vol. 2 Rev. 1
FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems – Provides the confidentiality, integrity, and availability impact model used for security categorization. - NIST Special Publication 800-37 Revision 2, Risk Management Framework for Information Systems and Organizations – Provides the Risk Management Framework supporting categorization, assessment, authorization, and continuous monitoring.
- NIST Special Publication 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations – Provides the security and privacy control catalog supporting the State and GovRAMP security frameworks.
- NIST Special Publication 800-137, Information Security Continuous Monitoring for Federal Information Systems and Organizations – Provides guidance for continuous monitoring and ongoing risk management.