Federal Cloud Compliance & RMF
Drive a federal cloud system from categorization to a signed ATO, then keep it authorized.
Tuition
$399
Advanced
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
10 hours
Estimated time
What you will be able to do
- Categorize a federal cloud system with FIPS 199 and NIST SP 800-60, and defend the impact level you assign.
- Draw an authorization boundary that cleanly separates what you own from what the cloud service provider owns.
- Select and tailor the correct FedRAMP baseline (Low, Moderate, or High) from NIST SP 800-53.
- Map control inheritance using the shared responsibility model and a customer responsibility matrix.
- Write a System Security Plan that an assessor and an authorizing official can actually follow.
- Plan a 3PAO assessment and turn its findings into a POA&M and a risk-based ATO recommendation.
- Run a FedRAMP continuous monitoring program: monthly scans, deviation requests, significant changes, and annual assessments.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
RMF and FedRAMP Foundations
Every authorization starts before a single control is written. This module frames the Risk Management Framework as a continuous lifecycle, places FedRAMP and its authorization paths (agency and the legacy JAB) inside it, and names the roles who own each decision. You then draw the authorization boundary for a cloud system and categorize it with FIPS 199 and NIST SP 800-60, the step that drives every control decision that follows.
2 lessons · 5 quiz questions
- 02
Control Selection and Inheritance
With your system categorized under FIPS 199, this module turns the impact level into a concrete, defensible control set. You select the matching FedRAMP baseline from NIST SP 800-53, tailor it with discipline instead of accepting it blindly, split every control between your team and your cloud provider through the shared responsibility model, and capture the result in a System Security Plan and Customer Responsibility Matrix that survive a 3PAO assessment.
2 lessons · 5 quiz questions · assignment
- 03
Assessment and the ATO Decision
An authorization stands or falls on the quality of its evidence. This module walks through planning and running a controls assessment (the Security Assessment Plan, the role of the 3PAO, and the Examine, Interview, and Test methods of NIST SP 800-53A) and then converting the Security Assessment Report into a Plan of Action and Milestones and a defensible, risk-based decision the authorizing official can sign.
2 lessons · 5 quiz questions
- 04
Continuous Monitoring and Ongoing Authorization
An ATO is not the finish line: it is a standing commitment to watch the system. This module runs the FedRAMP continuous monitoring program end to end, from monthly authenticated scans, reporting, and POA&M management to the events that test an authorization: significant changes, deviation requests, annual assessments, and the move toward ongoing authorization.
2 lessons · 5 quiz questions · assignment