FedRAMP Authorization: Why ‘Moderate’ Matters
FedRAMP, the federal program created to assess the security of cloud service providers (CSPs), saves time and cuts costs for U.S. government agencies that would otherwise conduct their own assessments. CSPs are granted authorizations at three impact levels: low (includes low-baseline and low-impact SaaS “li-SaaS”), medium, and high, aligned to the impact levels based on NIST guidelines. While the high-impact level protects the most sensitive government data, the moderate-impact level meets the needs of many agencies.
Why make the financial commitment, endure a rigorous authorization process and establish a continuous monitoring program when we could have simply self-attested our security controls for a li-SaaS classification? Because Cofense is a security company that prioritizes providing the highest level of protection to our customers, and a low-level certification just wasn’t good enough. That is why Cofense PhishMe is in the process of achieving FedRAMP moderate status. ...read more!