Open briri opened 10 months ago
Should turn FedRAMP authorization into an Epic and have those steps as tickets Not urgent for initial set up, will want it for own the line for government partnerships
This AWS solution might be interesting to explore - at least understand what this compliance framework covers and see if we are doing similar things already and what we might consider adding to our framework/architecture. The solution noted here supports FedRAMP.
https://aws.amazon.com/solutions/implementations/landing-zone-accelerator-on-aws/
The Landing Zone Accelerator on AWS solution deploys a foundational set of capabilities that is designed to align with AWS best practices and multiple global compliance frameworks. With this AWS Solution, you can better manage and govern your multi-account environment that have highly-regulated workloads and complex compliance requirements. When used in coordination with other AWS services, it provides a comprehensive, low-code solution across more than 35 AWS services.
I found this on the Educase Cloud Computing Connect group as they are offering discussions about this framework with other universities and establishing communities of practice. You can access Educause by logging in as UCOP institution.
We would be considered a "FedRAMP Tailored Low Impact-Software as a Service (Li-SaaS) provider". Li-SaaS systems because we provide a service (as opposed to infrastructure) and we do not store personal identifiable information (PII) beyond that is generally required for login capability (i.e. username, password, and email address).
It does require some administrative overhead. We would have to engage with a "Third-Party Assessment Organization (3PAO)" to become pre-authorized (3PAOs can be found in the FedRAMP marketplace). I'm not sure what that looks like from a time or dollar amount. There are then several HCVAT like documents that need to be filled out, and we would also need to engage with both the FedRAMP PMO and I suspect having someone at one of the agencies (e.g. DOT, CDC, etc.) helping us out would be helpful.
Things we should consider/do in the new system:
Achieving FedRAMP authorization for the system as a Low Impact-Software as a Service (Li-SaaS) provider involves several steps. Here are the key actions and considerations we should address:
It's crucial to engage with the FedRAMP PMO early in the process to seek guidance and ensure that you're following the correct procedures. Additionally, having a well-documented and secure system, along with collaboration with a FedRAMP-accredited 3PAO, will contribute to a smoother authorization process.