|This document provides the security control baselines. All of the security controls listed in the table are outlined in NIST 800-53 Rev. 4.
|Data Classification Tool
|This document helps service providers and governments determine what StateRAMP security category requirements to use to ensure their data is protected.
|Security Assessment Framework
|This document describes a general governance and security framework for StateRAMP.
|Continuous Monitoring Escalation Process
|This document explains the actions taken when a service provider fails to maintain an adequate continuous monitoring program.
|Continuous Monitoring Guide
|Continuous monitoring review procedures outline the process to examine each monthly package.
|Incident Communications Procedures
|This document describes the process for StateRAMP stakeholders to use when reporting information concerning information system security incidents or suspected information system security incidents.
|Vulnerability Scan Requirements Guide
|This guide describes the requirements for all vulnerability scans provided by service providers to StateRAMP for products with a Ready, Provisional, or Authorized status.
|3PAO Accreditation Process
|StateRAMP recognized FedRAMP authorized third party assessment organizations (3PAOs) to conduct independent audits.
|Appeals Committee Charter
|The Appeals Committee serves as the adjudication board for the Program Management Office determinations.
|FedRAMP JAB Attestation
|In an effort to provide recognition to those providers whose products have achieved a FedRAMP Authorization through Joint Authorization Board (JAB) approval, a new Federal JAB status has been created for providers who wish to list their product on the StateRAMP website.
|Provider Leadership Council Charter
|This charter outlines the duties and responsibilities of the StateRAMP Provider Leadership Council.
|Standards & Technical Committee Charter
|The Standards & Technical Committee makes recommendations for best practices and policies that guide cloud security requirements and verification.
|StateRAMP Adopted Bylaws
|This framework for bylaws was developed by the StateRAMP Steering Committee. As the Board of Directors is formed in late 2020, one of their first actions will be to adopt the bylaws for the organization.
|StateRAMP Approvals Committee Charter
|This charter outlines the duties and responsibilities of the StateRAMP Approvals Committee and their role in providing approvals for product security packages seeking an Authorized status.
|StateRAMP PMO Charter
|The PMO Charter defines the objectives, roles, and responsibilities associated with the StateRAMP Program Management Office (PMO).
|StateRAMP Steering Committee Charter
|The purpose of this charter is to define the objectives, membership, decision making, meeting schedule, and roles and responsibilities associated with the StateRAMP Steering Committee.
|Center for Digital Government Best Practice Guide for Cloud and As-a-Service Procurements
|The Best Practice Guide was created to provide government and industry with consensus-based advice and terms and conditions for cloud solution procurement models.
|Get Started With StateRAMP – Government Guide
|This guide explains the StateRAMP implementation process for governments.
|Sponsoring Government Brochure
|Learn about sponsoring government eligibility, how to become a sponsor, sponsor commitments, and how the StateRAMP PMO works to serve state and local governments.
|Minimum Mandates for Ready Status at Low Impact
|To achieve StateRAMP Ready status at a Low Impact Level, a service provider must meet the minimum mandatory requirements outlined in this document.
|Minimum Mandates for Ready Status at Moderate and High Impact
|To achieve StateRAMP Ready status at a Moderate or High Impact Level, a service provider must meet the minimum mandatory requirements outlined in this document.
|This document provides information about the StateRAMP organization, how to become a member, the process for engaging the PMO to complete a security review, requirements for government sponsorship, and how to list products on the Authorized Product List.
|StateRAMP PMO Fee Schedule
|This document provides an updated StateRAMP Program Management Fee Schedule, effective January 1, 2023.
|StateRAMP Security Assessment Framework
|This document provides a summary of the objectives, goals, and governance approach of StateRAMP, along with an outlined methodology to verify cloud security.
|StateRAMP Security Control Baselines Summary
|This document provides a summary of NIST 800-53 Rev. 4 security controls required for verification, by Security Impact Level Category. This summary is the result of ongoing collaboration with State leaders and cybersecurity experts.
|StateRAMP Provider Sponsor Requirements
|This document outlines the process (including government sponsorship requirements) for a vendor’s offering to be listed as StateRAMP Authorized on StateRAMP’s Authorized Product List (APL).
|Significant Change Form Template
|Service providers are requirements to submit this completed form to StateRAMP and receive StateRAMP approval prior to implementing a significant change to a system with an existing StateRAMP Authorization.
|Vulnerability Deviation Request Form
|When a service provider identifies a vulnerability that potentially warrants different handling than normally required by StateRAMP, they may submit a deviation request to StateRAMP using this form.