Skip to main content
Course

Federal Cloud Security Foundations

Know the rules, run the framework, draw the boundary.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

8 hours

Estimated time

What you will be able to do

  • Explain how FISMA, the NIST Risk Management Framework, and FedRAMP relate, and name which authority requires each.
  • Walk a cloud system through the seven RMF steps from Prepare to Monitor.
  • Categorize a federal system with FIPS 199 and select the matching NIST 800-53 control baseline.
  • Compare the FedRAMP authorization paths and map a system to the Low, Moderate, or High impact level.
  • Identify the core FedRAMP package artifacts (SSP, SAP, SAR, POA&M) and explain what each one proves.
  • Draw a defensible authorization boundary for a cloud system and justify what falls inside it.
  • Read a customer responsibility matrix and separate inherited controls from customer-implemented ones across IaaS, PaaS, and SaaS.
  • Describe how continuous monitoring keeps an Authorization to Operate valid after it is granted.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    The Federal Security Mandate

    Federal systems answer to a stack of law, policy, and standards that private-sector security does not. This module maps how FISMA sets the legal requirement, how the NIST Risk Management Framework turns it into a repeatable process, and where FedRAMP enters as the cloud-specific program. By the end you can explain who requires what, and why each layer exists.

    2 lessons · 5 quiz questions

  2. 02

    Running the Risk Management Framework

    The Risk Management Framework is the seven-step engine behind every federal authorization. This module walks the steps from Prepare through Monitor, then goes deep on the decision that drives everything else: categorizing a system with FIPS 199 and selecting a NIST SP 800-53 control baseline. You finish able to take a system from an impact analysis to a defensible baseline recommendation on the path to an Authorization to Operate.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Inside FedRAMP

    FedRAMP applies the NIST Risk Management Framework to cloud services so a single authorization can be trusted and reused across federal agencies. This module walks through the authorization paths, the Low, Moderate, and High impact levels, the security package a provider must produce and defend, the role of the independent 3PAO, and why continuous monitoring never really stops.

    2 lessons · 5 quiz questions

  4. 04

    Boundary and Shared Responsibility

    Two questions decide every cloud authorization: where the system ends, and who secures each part. This module teaches you to draw and defend an authorization boundary and to read a customer responsibility matrix across IaaS, PaaS, and SaaS. You finish able to separate the controls you inherit from the ones you must implement yourself.

    2 lessons · 5 quiz questions · assignment