MarketplaceCybersecurityFedRAMP Controls
CybersecurityStandard

FedRAMP Controls

FedRAMP Security Controls Baseline rev 5

The FedRAMP Security Controls Baseline is a standardized set of cloud security requirements based on NIST SP 800-53 that defines the minimum security controls cloud service providers must implement to protect federal data and achieve FedRAMP authorization.

Overview

The FedRAMP Security Controls Baseline is a standardized set of security requirements established by the Federal Risk and Authorization Management Program (FedRAMP) for cloud service providers that offer services to U.S. federal agencies. Based on the NIST Special Publication (SP) 800-53 security and privacy controls framework, the baseline defines the minimum safeguards required to protect federal information processed, stored, or transmitted in cloud environments. FedRAMP organizes these requirements into multiple impact levels, including Low, Moderate, and High, with each baseline containing security controls tailored to the potential impact that a loss of confidentiality, integrity, or availability could have on government operations, assets, or individuals. The FedRAMP Security Controls Baseline provides a consistent approach to security assessment, authorization, and continuous monitoring, helping federal agencies evaluate cloud services while ensuring compliance with federal cybersecurity requirements and risk management practices.

Related in Cybersecurity

CybersecurityGuideline

NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

NIST SP 800-172 elaborates enhanced security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations. It aims to mitigate risks posed by Advanced Persistent Threats (APT) through a defense-in-depth approach, building on the foundational requirements in NIST SP 800-171.

National Institute of Standards and Technology (NIST) • United States

View details
CybersecurityRegulation

Dubai ISR — Dubai Government Information Security Regulation

The Dubai Government Information Security Regulation (ISR) provides standards to ensure the continuity of critical business processes and minimize information security risks for Dubai Government Entities. It defines minimum requirements for information security controls and aims to maintain confidentiality, integrity, and availability of government information.

Dubai Government • Dubai • v3

View details
CybersecurityFramework

DSPF — Defence Security Principles Framework

The Defence Security Principles Framework (DSPF) is the Australian Department of Defence's principles-based security framework that provides governance, security principles, and controls to help Defence personnel manage risks and protect Defence people, information, assets, and operations in alignment with the PSPF.

Australian Government • Australian • v2 July 2018

View details
CybersecurityFramework

CPG 1.0 — Cross-Sector Cybersecurity Performance Goals

The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful.

Cybersecurity and Infrastructure Security Agency (CISA) • United States • v1.0.1

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call