{"id":2243,"date":"2023-08-31T18:58:26","date_gmt":"2023-08-31T22:58:26","guid":{"rendered":"https:\/\/eptura.wpengine.com\/?p=2243"},"modified":"2024-09-10T00:33:39","modified_gmt":"2024-09-10T04:33:39","slug":"demystifying-fedramp-compliance-and-authorization","status":"publish","type":"post","link":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/","title":{"rendered":"Demystifying FedRAMP compliance and authorization"},"content":{"rendered":"<p>As a government agency, there are many advantages to being able to tap into cloud technologies. From eliminating time-consuming manual tasks and reducing paperwork, cloud technologies offer a spectrum of efficient and effective improvements over traditional methods. Plus, software as a service (SaaS) subscription-based models can help reduce annual information technology costs.<\/p>\n<p>To implement these technologies, however, you\u2019ll need to comply with the Federal Risk and Authorization Management Program known as \u00a0FedRAMP provides a standardized approach for assessing and complying with government security controls, authorizing cloud products and services, and proving continuous monitoring of systems. It&#8217;s managed by the FedRAMP Program Management Office (PMO).<\/p>\n<p>FedRAMP authorization can seem daunting, but if you have the right resources and preparation in place, the process can be streamlined and simplified. In fact, there\u2019s a lot less for a Federal agency to do than you might think. The burden is predominantly on the cloud service provider (CSP) whose services you wish to use and its independent assessor over your team and internal resources.<\/p>\n<p>There are several common myths, misconceptions, and questions about FedRAMP requirements and processes \u2013 and a few benefits to understand given the investment and effort of the program.<\/p>\n<p>To help clarify, we spoke with expert <a href=\"https:\/\/www.coalfire.com\/about\/executive-team\">James Masella<\/a>, Vice President of Compliance Advisory Services, at <a href=\"https:\/\/www.coalfire.com\/\">Coalfire<\/a> \u2013 a leading provider of IT security assessments for many security standards and payments frameworks and programs, including FedRAMP support.<\/p>\n<p>Masella has been working in IT for 20 years \u2013 15 of them focused on security assessments for Federal controls, most prominently, helping organizations comply with <a href=\"https:\/\/www.nist.gov\/cybersecurity\">National Institute of Standards and Technology (NIST) cybersecurity controls<\/a>. Over his career, Masella has accomplished over 70 FedRAMP compliance and assessment projects \u2013 and has been working on them since the program\u2019s infancy in 2015. He\u2019s been with Coalfire for eight years.<\/p>\n<h2>What is FedRAMP?<\/h2>\n<p>If you\u2019re evaluating cloud technologies, such as a <a href=\"https:\/\/eptura.com\/our-platform\/\">workplace and asset maintenance platform<\/a>, it helps to have a background in the evolution of FedRAMP since there are many different cybersecurity compliance and controls to manage. In fact, the program was created specifically with this knowledge. The entire goal of FedRAMP is to accelerate the adoption of secure cloud solutions in the Federal government.<\/p>\n<p>It streamlines the authorization process for CSPs and improves confidence in the security of cloud solutions. FedRAMP was created by the General Services Administration (GSA) in partnership with the US Department of Defense (DoD) and NIST.<\/p>\n<p>\u201cThe big problem that FedRAMP was meant to solve was the Federal government knew it needed to modernize its IT infrastructure because their model was not sustainable,\u201d explains Masella. \u201cCommercial cloud services were a lot more affordable than the way much of the government manages IT infrastructure and provided better services.\u201d<\/p>\n<p>The challenge is having assurance that the security of those commercial cloud services is meeting the requirements for the Federal government. And under the Federal Information Security Modernization Act (FISMA), every federal agency can implement its own security plan if it follows the guidelines of the law \u2013 which also include audits and independent assessments.<\/p>\n<p>FedRAMP pulls that all under one umbrella and allows all Federal agencies to leverage independent assessors to reduce duplicate effort within audit and assessment work. But FedRAMP is not a certification \u2013 it\u2019s a compliance framework within a Federal program that an organization is either authorized to be a part of or not.<\/p>\n<p>\u201cFedRAMP is a different animal,\u201d says Masella. \u201cYou actually are building an information system for Federal government use and the government is authorizing that system for use for Federal data.&#8221;<\/p>\n<p>Any vendor who has gone through an extensive audit process can be listed in the <a href=\"https:\/\/marketplace.fedramp.gov\/products\">FedRAMP marketplace<\/a>, so Federal agencies can easily find and procure services without having to do additional research or due diligence. It makes it easier for departments, such as the Department of Homeland Security (DHS), DoD, or healthcare organizations including the Centers for Medicare &amp; Medicaid Services (CMS) to purchase products from vetted vendors quickly while reducing costs associated with IT resources.<\/p>\n<p>The good news is there are over 300 authorizations on the FedRAMP marketplace today, and some of them are large, some are small. They&#8217;ve all solved many of the challenges and issues already, relays Masella.<\/p>\n<h2>Delineation of work under FedRAMP: Who is responsible and for what?<\/h2>\n<p>The PMO is responsible for managing documents, such as policies, procedures, standards, guidance documents, templates, checklists, etc., which are used throughout all stages of authorization. The <a href=\"https:\/\/www.fedramp.gov\/jab-authorization\/\">FedRAMP Joint Authorization Board<\/a> (JAB) reviews all provisional Authority to Operate (ATO) packages before they are authorized.<\/p>\n<p>The 3PAOs \u2013 Third Party Assessment Organizations \u2013 conduct independent security assessments for agencies before issuing a Provisional ATO. These 3PAOs assess each system\u2019s compliance with NIST 800-53 standards, as well as other requirements specified by each agency or department at four different Impact Levels ranging from Low to High. Coalfire is an example of a 3PAO.<\/p>\n<p>\u201cIn the case where a CSP has engaged an advisor, the advisor entities are doing all of the work,\u201d says Matella. \u201cThe [government] agency just has their due diligence under the law to review the risk. That&#8217;s it. It&#8217;s the same thing they would have to do if they were the second agency or the last agency or the agency in the middle. There is no difference.\u201d<\/p>\n<p>The heavy lift and burden are accomplished by the 3PAOs and the cloud service provider.<\/p>\n<h2>The requirements for FedRAMP compliance<\/h2>\n<p>Depending on the risk associated with a particular service, organizations must demonstrate their commitment to security to gain authorization from the JAB. The requirements range from basic NIST 800-53 Rev 4 controls at Low Impact Level (Level 1) all the way up to DHS Risk Management Framework regulations and additional physical protection measures at High Impact Level (Level 3).<\/p>\n<p>Once a Provisional Authority to Operate (PATO) has been granted, it is valid for three years, however organizations are expected to continuously monitor their systems and update any changes made since initial authorization was granted.<\/p>\n<h2>Preparing for FedRAMP: What you need to know<\/h2>\n<p>If this is the first time you are dealing with FedRAMP, it\u2019s important to understand some of the most common issues that can arise. Many of these will be the burden of the CSP you wish to use \u2013 but it\u2019s better to know what they are upfront.<\/p>\n<p>First, it\u2019s important to communicate to the CSP your specific agency\u2019s policies on who can access information. Some hurdles involve the standards and requirements themselves, relays Matella. These include technology and process compliance areas, such as validated encryption, requirements of internal flows, and connections to external services \u2014 they all must be FedRAMP authorized.<\/p>\n<p>\u201cIn many cases, it&#8217;s not a Fed RAMP requirement, but it can be a requirement from agencies that only US persons or US citizens can actually access the production environments,\u201d he says. \u201cAnd many of these commercial cloud services are supported by offshore support and many have a \u2018follow the sun\u2019 (operational) model.\u201d<\/p>\n<p>As Masella points out, these issues have been dealt with before by other agencies and CSPs, but it\u2019s one that needs to be addressed and understood from the outset.<\/p>\n<p>Secondly, CSPs themselves may think they know compliance, but it can be more work than they know. Many IT leaders assume they have the expertise in-house to handle FedRAMP since they already have an internal security team. Just because they have a robust engineering team, it doesn\u2019t mean it\u2019s going to be easy to architect a system to meet FedRAMP requirements.<\/p>\n<p>\u201cMany times, the engineering teams are great at designing infrastructure and applications, but once you take away a lot of the tools that they have been using or you have to implement some new measures that they didn&#8217;t have to have before, this can complicate things,\u201d says Masella.<\/p>\n<p>For example, perhaps a CSP doesn\u2019t perform vulnerability scanning internally or they don\u2019t do file integrity management today and must implement and use it. Now they&#8217;re having to decide on new tool sets \u2013 which take time to evaluate and get up to speed.<\/p>\n<p>The other problem area Masella sees a lot is not having the business case worked out and detailed enough for the investment. If the CSP hasn&#8217;t done enough market research, they can easily get derailed.<\/p>\n<p>\u201c[A CSP] might not be able to get that first initial authorizing agency, might not get on the marketplace, might start the investment and it begins to get pretty big, and the return-on-investment case might not be there,\u201d says Masella.<\/p>\n<p>The best guidance is for the CSP to work with an experienced, third-party FedRAMP advisor preparation provider. And as he points out, many of the challenges and pitfalls can be avoided since much of it has been sorted out already. Getting this kind of information upfront will help you speed up your FedRAMP authorization process overall.<\/p>\n<p>&nbsp;<\/p>\n<h2>FedRAMP checklist<\/h2>\n<h3>Common FedRAMP questions<\/h3>\n<ul>\n<li>Is FedRAMP a certification?<\/li>\n<li>How long should it take to finish the FedRAMP process?<\/li>\n<li>What should be prioritized first when seeking FedRAMP authorization?<\/li>\n<li>Can artificial intelligence help speed up the process?<\/li>\n<\/ul>\n<h3>Common FedRAMP misconceptions<\/h3>\n<ul>\n<li>Our agency will have to do a lot of heavy lifting of the work.<\/li>\n<li>The CSPs engineering team work on security compliance already, so FedRAMP work should be easy.<\/li>\n<li>FedRAMP takes a lot longer than it should.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<table border=\"1px\" cellspacing=\"0\" cellpadding=\"15px\">\n<tbody>\n<tr>\n<td>FedRAMP Questions \/ Misconceptions<\/td>\n<td>Answers<\/td>\n<\/tr>\n<tr>\n<td>Is FedRAMP a certification?<\/td>\n<td>No, it\u2019s a program. You use a compliance framework, audits, assessments to be authorized to be within FedRAMP.<\/td>\n<\/tr>\n<tr>\n<td>How long should it take to finish the FedRAMP process?<\/td>\n<td>It depends. Very fast is 90 days. Most common is 9 to 12 months depending on prioritization and changes needed.<\/td>\n<\/tr>\n<tr>\n<td>What should be prioritized first when seeking FedRAMP authorization?<\/td>\n<td>Gaps between FedRAMP framework and your current state of compliance.<\/td>\n<\/tr>\n<tr>\n<td>Can artificial intelligence help speed up the process?<\/td>\n<td>AI has a significant role to play in automating the creation and review of documentation packages which could speed up the process and increase the number of services in the marketplace, but it\u2019s not in widespread use yet.<\/td>\n<\/tr>\n<tr>\n<td>Our Federal agency will have to do a heavy lift.<\/td>\n<td>Actually, the CSP we want to use and its 3PAO will do the bulk of the technology and process compliance. Our agency will perform due diligence on risk under the law.<\/td>\n<\/tr>\n<tr>\n<td>The CSPs engineering team work on security compliance already, so FedRAMP work should be easy.<\/td>\n<td>This is the most common pitfall: A large engineering team does not mean you will easily meet FedRAMP requirements.<\/td>\n<\/tr>\n<tr>\n<td>FedRAMP takes a lot longer than it should.<\/td>\n<td>Preparation with CSPs and independent guidance will help speed up the process. Know your specific agency information access policies and communicate them upfront to CSPs. Encourage CSPs to work with a 3PAO.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>FedRAMP helps government agencies like yours make sure your data remains secure while reducing duplication when purchasing compliant offerings in the <a href=\"https:\/\/marketplace.fedramp.gov\/products\">approved marketplace<\/a>. It also provides assurance that any cloud solution used meets pre-defined security requirements, so that you can have peace of mind knowing your data is being always kept safe and secure.<\/p>\n<p>After you go through the FedRAMP process for the first time, it will open up the door to a world of new and evolving cloud technologies forever.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>What will the workplace of tomorrow look like for government organizations? <a href=\"https:\/\/lp.eptura.com\/events-flex-23-federal.html?utm_campaign=2023Q3-Americas-Events-Flex23-Federal-DC&amp;utm_medium=website&amp;utm_source=eptura&amp;utm_content=blog\">Join us at Flex\/23 D.C.<\/a> to discover how Archibus is built to support the unique needs of these vital services<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As a government agency, there are many advantages to being able to tap into cloud technologies. From eliminating time-consuming manual tasks and reducing paperwork, cloud technologies offer a spectrum of efficient and effective improvements over traditional methods. <\/p>\n","protected":false},"author":26,"featured_media":2244,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":"","_wpscp_schedule_draft_date":"","_wpscp_schedule_republish_date":"","_wpscppro_advance_schedule":false,"_wpscppro_advance_schedule_date":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[7,1],"tags":[],"class_list":["post-2243","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-eptura"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.5 (Yoast SEO v26.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Demystifying FedRAMP compliance and authorization |<\/title>\n<meta name=\"description\" content=\"As a government agency, there are many advantages to being able to tap into cloud technologies. From eliminating time-consuming manual tasks and reducing paperwork, cloud technologies offer a spectrum of efficient and effective improvements over traditional methods.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Demystifying FedRAMP compliance and authorization\" \/>\n<meta property=\"og:description\" content=\"As a government agency, there are many advantages to being able to tap into cloud technologies. From eliminating time-consuming manual tasks and reducing paperwork, cloud technologies offer a spectrum of efficient and effective improvements over traditional methods.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/\" \/>\n<meta property=\"og:site_name\" content=\"Eptura\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/EpturaWork\/\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-31T22:58:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-10T04:33:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eptura.com\/wp-content\/uploads\/2023\/08\/fedramp.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"624\" \/>\n\t<meta property=\"og:image:height\" content=\"351\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Jonathan Davis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@epturawork\" \/>\n<meta name=\"twitter:site\" content=\"@epturawork\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jonathan Davis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/\"},\"author\":{\"name\":\"Jonathan Davis\",\"@id\":\"https:\/\/eptura.com\/#\/schema\/person\/2e140d3d2f77b87152b5e2ba941b9158\"},\"headline\":\"Demystifying FedRAMP compliance and authorization\",\"datePublished\":\"2023-08-31T22:58:26+00:00\",\"dateModified\":\"2024-09-10T04:33:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/\"},\"wordCount\":1910,\"publisher\":{\"@id\":\"https:\/\/eptura.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/eptura.com\/wp-content\/uploads\/2023\/08\/fedramp.webp\",\"articleSection\":[\"Blog\",\"Eptura\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/\",\"url\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/\",\"name\":\"Demystifying FedRAMP compliance and authorization |\",\"isPartOf\":{\"@id\":\"https:\/\/eptura.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/eptura.com\/wp-content\/uploads\/2023\/08\/fedramp.webp\",\"datePublished\":\"2023-08-31T22:58:26+00:00\",\"dateModified\":\"2024-09-10T04:33:39+00:00\",\"description\":\"As a government agency, there are many advantages to being able to tap into cloud technologies. From eliminating time-consuming manual tasks and reducing paperwork, cloud technologies offer a spectrum of efficient and effective improvements over traditional methods.\",\"breadcrumb\":{\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#primaryimage\",\"url\":\"https:\/\/eptura.com\/wp-content\/uploads\/2023\/08\/fedramp.webp\",\"contentUrl\":\"https:\/\/eptura.com\/wp-content\/uploads\/2023\/08\/fedramp.webp\",\"width\":624,\"height\":351,\"caption\":\"FedRamp authorization process\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/eptura.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Demystifying FedRAMP compliance and authorization\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/eptura.com\/#website\",\"url\":\"https:\/\/eptura.com\/\",\"name\":\"Eptura\",\"description\":\"Work your world\",\"publisher\":{\"@id\":\"https:\/\/eptura.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/eptura.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/eptura.com\/#organization\",\"name\":\"Eptura\",\"url\":\"https:\/\/eptura.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/eptura.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/eptura.com\/wp-content\/uploads\/2024\/03\/eptura-dark-svg-TM-8.png\",\"contentUrl\":\"https:\/\/eptura.com\/wp-content\/uploads\/2024\/03\/eptura-dark-svg-TM-8.png\",\"width\":1280,\"height\":800,\"caption\":\"Eptura\"},\"image\":{\"@id\":\"https:\/\/eptura.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/EpturaWork\/\",\"https:\/\/x.com\/epturawork\",\"https:\/\/www.linkedin.com\/company\/eptura\/\",\"https:\/\/twitter.com\/epturawork\",\"https:\/\/www.youtube.com\/channel\/UC6hdVbsn41BZxfIYmPUdCWQ\"],\"description\":\"A global worktech company that provides software solutions for workplaces, people, and assets that enable everyone to reach their full potential.\",\"legalName\":\"Eptura\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/eptura.com\/#\/schema\/person\/2e140d3d2f77b87152b5e2ba941b9158\",\"name\":\"Jonathan Davis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/eptura.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/eptura.com\/wp-content\/uploads\/2024\/02\/jonathan_davis-96x96.png\",\"contentUrl\":\"https:\/\/eptura.com\/wp-content\/uploads\/2024\/02\/jonathan_davis-96x96.png\",\"caption\":\"Jonathan Davis\"},\"description\":\"As a content creator at Eptura, Jonathan Davis covers asset management, maintenance software, and SaaS solutions, delivering thought leadership with actionable insights across industries such as fleet, manufacturing, healthcare, and hospitality. Jonathan\u2019s writing focuses on topics to help enterprises optimize their operations, including building lifecycle management, digital twins, BIM for facility management, and preventive and predictive maintenance strategies. With a master's degree in journalism and a diverse background that includes writing textbooks, editing video game dialogue, and teaching English as a foreign language, Jonathan brings a versatile perspective to his content creation.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/jonathan-t-davis\/\"],\"jobTitle\":\"Senior Content Writer\",\"worksFor\":\"Eptura\",\"url\":\"https:\/\/eptura.com\/discover-more\/blog\/author\/jonathan-davis\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Demystifying FedRAMP compliance and authorization |","description":"As a government agency, there are many advantages to being able to tap into cloud technologies. From eliminating time-consuming manual tasks and reducing paperwork, cloud technologies offer a spectrum of efficient and effective improvements over traditional methods.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/","og_locale":"en_US","og_type":"article","og_title":"Demystifying FedRAMP compliance and authorization","og_description":"As a government agency, there are many advantages to being able to tap into cloud technologies. From eliminating time-consuming manual tasks and reducing paperwork, cloud technologies offer a spectrum of efficient and effective improvements over traditional methods.","og_url":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/","og_site_name":"Eptura","article_publisher":"https:\/\/www.facebook.com\/EpturaWork\/","article_published_time":"2023-08-31T22:58:26+00:00","article_modified_time":"2024-09-10T04:33:39+00:00","og_image":[{"width":624,"height":351,"url":"https:\/\/eptura.com\/wp-content\/uploads\/2023\/08\/fedramp.webp","type":"image\/webp"}],"author":"Jonathan Davis","twitter_card":"summary_large_image","twitter_creator":"@epturawork","twitter_site":"@epturawork","twitter_misc":{"Written by":"Jonathan Davis","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#article","isPartOf":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/"},"author":{"name":"Jonathan Davis","@id":"https:\/\/eptura.com\/#\/schema\/person\/2e140d3d2f77b87152b5e2ba941b9158"},"headline":"Demystifying FedRAMP compliance and authorization","datePublished":"2023-08-31T22:58:26+00:00","dateModified":"2024-09-10T04:33:39+00:00","mainEntityOfPage":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/"},"wordCount":1910,"publisher":{"@id":"https:\/\/eptura.com\/#organization"},"image":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#primaryimage"},"thumbnailUrl":"https:\/\/eptura.com\/wp-content\/uploads\/2023\/08\/fedramp.webp","articleSection":["Blog","Eptura"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/","url":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/","name":"Demystifying FedRAMP compliance and authorization |","isPartOf":{"@id":"https:\/\/eptura.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#primaryimage"},"image":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#primaryimage"},"thumbnailUrl":"https:\/\/eptura.com\/wp-content\/uploads\/2023\/08\/fedramp.webp","datePublished":"2023-08-31T22:58:26+00:00","dateModified":"2024-09-10T04:33:39+00:00","description":"As a government agency, there are many advantages to being able to tap into cloud technologies. From eliminating time-consuming manual tasks and reducing paperwork, cloud technologies offer a spectrum of efficient and effective improvements over traditional methods.","breadcrumb":{"@id":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#primaryimage","url":"https:\/\/eptura.com\/wp-content\/uploads\/2023\/08\/fedramp.webp","contentUrl":"https:\/\/eptura.com\/wp-content\/uploads\/2023\/08\/fedramp.webp","width":624,"height":351,"caption":"FedRamp authorization process"},{"@type":"BreadcrumbList","@id":"https:\/\/eptura.com\/discover-more\/blog\/demystifying-fedramp-compliance-and-authorization\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/eptura.com\/"},{"@type":"ListItem","position":2,"name":"Demystifying FedRAMP compliance and authorization"}]},{"@type":"WebSite","@id":"https:\/\/eptura.com\/#website","url":"https:\/\/eptura.com\/","name":"Eptura","description":"Work your world","publisher":{"@id":"https:\/\/eptura.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/eptura.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/eptura.com\/#organization","name":"Eptura","url":"https:\/\/eptura.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/eptura.com\/#\/schema\/logo\/image\/","url":"https:\/\/eptura.com\/wp-content\/uploads\/2024\/03\/eptura-dark-svg-TM-8.png","contentUrl":"https:\/\/eptura.com\/wp-content\/uploads\/2024\/03\/eptura-dark-svg-TM-8.png","width":1280,"height":800,"caption":"Eptura"},"image":{"@id":"https:\/\/eptura.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/EpturaWork\/","https:\/\/x.com\/epturawork","https:\/\/www.linkedin.com\/company\/eptura\/","https:\/\/twitter.com\/epturawork","https:\/\/www.youtube.com\/channel\/UC6hdVbsn41BZxfIYmPUdCWQ"],"description":"A global worktech company that provides software solutions for workplaces, people, and assets that enable everyone to reach their full potential.","legalName":"Eptura"},{"@type":"Person","@id":"https:\/\/eptura.com\/#\/schema\/person\/2e140d3d2f77b87152b5e2ba941b9158","name":"Jonathan Davis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/eptura.com\/#\/schema\/person\/image\/","url":"https:\/\/eptura.com\/wp-content\/uploads\/2024\/02\/jonathan_davis-96x96.png","contentUrl":"https:\/\/eptura.com\/wp-content\/uploads\/2024\/02\/jonathan_davis-96x96.png","caption":"Jonathan Davis"},"description":"As a content creator at Eptura, Jonathan Davis covers asset management, maintenance software, and SaaS solutions, delivering thought leadership with actionable insights across industries such as fleet, manufacturing, healthcare, and hospitality. Jonathan\u2019s writing focuses on topics to help enterprises optimize their operations, including building lifecycle management, digital twins, BIM for facility management, and preventive and predictive maintenance strategies. With a master's degree in journalism and a diverse background that includes writing textbooks, editing video game dialogue, and teaching English as a foreign language, Jonathan brings a versatile perspective to his content creation.","sameAs":["https:\/\/www.linkedin.com\/in\/jonathan-t-davis\/"],"jobTitle":"Senior Content Writer","worksFor":"Eptura","url":"https:\/\/eptura.com\/discover-more\/blog\/author\/jonathan-davis\/"}]}},"_links":{"self":[{"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/posts\/2243","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/users\/26"}],"replies":[{"embeddable":true,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/comments?post=2243"}],"version-history":[{"count":0,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/posts\/2243\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/media\/2244"}],"wp:attachment":[{"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/media?parent=2243"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/categories?post=2243"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eptura.com\/wp-json\/wp\/v2\/tags?post=2243"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}