Skip to main content
Course

Federal Cloud Compliance & RMF

Drive a federal cloud system from categorization to a signed ATO, then keep it authorized.

Advanced

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

10 hours

Estimated time

What you will be able to do

  • Categorize a federal cloud system with FIPS 199 and NIST SP 800-60, and defend the impact level you assign.
  • Draw an authorization boundary that cleanly separates what you own from what the cloud service provider owns.
  • Select and tailor the correct FedRAMP baseline (Low, Moderate, or High) from NIST SP 800-53.
  • Map control inheritance using the shared responsibility model and a customer responsibility matrix.
  • Write a System Security Plan that an assessor and an authorizing official can actually follow.
  • Plan a 3PAO assessment and turn its findings into a POA&M and a risk-based ATO recommendation.
  • Run a FedRAMP continuous monitoring program: monthly scans, deviation requests, significant changes, and annual assessments.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    RMF and FedRAMP Foundations

    Every authorization starts before a single control is written. This module frames the Risk Management Framework as a continuous lifecycle, places FedRAMP and its authorization paths (agency and the legacy JAB) inside it, and names the roles who own each decision. You then draw the authorization boundary for a cloud system and categorize it with FIPS 199 and NIST SP 800-60, the step that drives every control decision that follows.

    2 lessons · 5 quiz questions

  2. 02

    Control Selection and Inheritance

    With your system categorized under FIPS 199, this module turns the impact level into a concrete, defensible control set. You select the matching FedRAMP baseline from NIST SP 800-53, tailor it with discipline instead of accepting it blindly, split every control between your team and your cloud provider through the shared responsibility model, and capture the result in a System Security Plan and Customer Responsibility Matrix that survive a 3PAO assessment.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Assessment and the ATO Decision

    An authorization stands or falls on the quality of its evidence. This module walks through planning and running a controls assessment (the Security Assessment Plan, the role of the 3PAO, and the Examine, Interview, and Test methods of NIST SP 800-53A) and then converting the Security Assessment Report into a Plan of Action and Milestones and a defensible, risk-based decision the authorizing official can sign.

    2 lessons · 5 quiz questions

  4. 04

    Continuous Monitoring and Ongoing Authorization

    An ATO is not the finish line: it is a standing commitment to watch the system. This module runs the FedRAMP continuous monitoring program end to end, from monthly authenticated scans, reporting, and POA&M management to the events that test an authorization: significant changes, deviation requests, annual assessments, and the move toward ongoing authorization.

    2 lessons · 5 quiz questions · assignment