FedRAMP Foundations
Your on-ramp to FedRAMP and federal cloud authorization.
Tuition
$349
Beginner
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
8 hours
Estimated time
What you will be able to do
- Explain why FedRAMP exists and how it builds on FISMA and NIST SP 800-53.
- Describe the three cloud service models (IaaS, PaaS, SaaS) and what counts as a Cloud Service Offering.
- Categorize a system into the Low, Moderate, or High impact level using FIPS 199 and select the matching control baseline.
- Distinguish the roles of the Cloud Service Provider, the third party assessment organization (3PAO), and the sponsoring agency.
- Compare the agency authorization path with the PMO-managed path and explain when each applies.
- Identify the core authorization package documents: the SSP, SAP, SAR, and POA&M.
- Trace a cloud service through the readiness, authorization, and continuous monitoring phases.
- Read a FedRAMP Marketplace listing and interpret the Ready, In Process, and Authorized designations.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Why FedRAMP Exists
FedRAMP lets one rigorous security review serve many federal agencies instead of each agency starting over. This module explains the duplication problem the program solves, its legal footing in the FedRAMP Authorization Act and its roots in FISMA and NIST, and how to read the FedRAMP Marketplace along with the Ready, In Process, and Authorized designations.
2 lessons · 5 quiz questions
- 02
Cloud Offerings and Impact Levels
Before a service can be authorized, you have to know exactly what is being authorized and how sensitive its data is. This module explains the three cloud service models (IaaS, PaaS, and SaaS), what makes up a Cloud Service Offering and its authorization boundary, and how FIPS 199 sorts systems into Low, Moderate, and High impact. You will see how each impact level maps to a NIST SP 800-53 control baseline.
2 lessons · 5 quiz questions · assignment
- 03
The Key Roles
FedRAMP works because no single party both does the work and grades it. This module introduces the four parties that share the job. The Cloud Service Provider builds, operates, and documents the system. The accredited, independent 3PAO tests it and reports what it finds. The sponsoring agency's Authorizing Official weighs the risk and signs the Authority to Operate. The FedRAMP PMO, with the FedRAMP Board above it, sets the standards and keeps the program consistent. By the end you can name who produces each artifact, who signs the ATO, and why independence and oversight are built into the structure.
2 lessons · 5 quiz questions
- 04
Authorization Paths and the Package
Bring the players and the paperwork together into one authorization journey. This module compares the agency authorization path with the centrally PMO-managed path, walks the three phases of readiness, authorization, and continuous monitoring, and unpacks the four core package documents (SSP, SAP, SAR, and POA&M) that carry the decision. By the end you can follow a real cloud service from its first readiness review through monthly continuous monitoring.
2 lessons · 5 quiz questions · assignment