FedRAMP is governed by different
Executive Branch entities that collaborate to develop, manage, and operate the program. These entities include: • The
Office of Management and Budget (OMB): The governing body that issued the FedRAMP policy memo, which defines the key requirements and capabilities of the program • The Joint Authorization Board (JAB): The primary governance and decision-making body for FedRAMP comprises the chief information officers (CIOs) from the
Department of Homeland Security (DHS),
General Services Administration (GSA), and
Department of Defense (DOD) The FedRAMP Policy Memo requires federal agencies to use FedRAMP when assessing, authorizing, and continuously monitoring cloud services in order to aid agencies in the authorization process as well as save government resources and eliminate duplicative efforts. FedRAMP's security baselines are derived from
NIST SP 800-53 (as revised) with a set of control enhancements that pertain to the unique security requirements of cloud computing. ==Third-party assessment organizations==