CHAPTER 27
Assuring Compliance with Government Certification and Accreditation Regulations
Sarbari Gupta
Electrosoft Services, Inc.
Reston, Virginia
Contents
27.2 Office of Management and Budget Circular A-130, Appendix III
27.3 Federal Information Security Management Act
27.4 NIST Risk Management Framework
27.5 Department of Defense (DoD) Risk Management Framework
27.6 Federal Risk and Authorization Management Program (FedRAMP)
27.6.1 FedRAMP Assessment (Certification)
27.6.2 FedRAMP Authorization (Accreditation)
27.6.2.1 JAB Provisional Authorization to Operate (JAB p-ATO)
27.6.2.2 Agency Authorization to Operate (Agency ATO)
27.6.3 Leveraging FedRAMP Authorizations