The Defense Information Systems Agency is looking the General Services Administration’s FedRAMP high baseline as the starting point for a “high-plus” standard that would pertain to the most highly sensitive data.
The public comment period on the Federal Risk and Authorization Management (FedRAMP) draft high baseline closes March 13. The high baseline will authorize third-party cloud service providers to host sensitive data, including personally identifiable information and health records — information that could do serious harm if leaked.
Download: FedRAMP high baseline draft document
The baseline will not cover classified or unclassified controlled information, however. Defense agencies and other departments looking to put highly sensitive data (level 5 and 6) in the cloud will be looking to implement a FedRAMP high-plus, using the high baseline as a starting point with added, agency-specific requirements grafted on, as outlined in the Defense Information Systems Agency’s most recent cloud security guidance.
More: DISA security guide outlines future of DoD cloud
The FedRAMP program office has already received more than 60 comments from 10 agencies and industry representatives, according to FedRAMP Director Matt Goodrich. So far, the comments have generally fallen into one of three areas:
- More clearly defining parameter selections;
- Establishing who is responsible for implementing controls for various service models, such as Infrastructure-as-a-Service or Software-as-a-Service; and
- Additional guidance on how the controls apply to virtual boundaries and services.
After Friday’s deadline, the FedRAMP PMO will bring together a “tiger team” from several federal agencies to help sift through the comments.
A second draft is expected this summer, with another 45-day comment period. The final high baseline is on track to be released before the end of 2015, Goodrich said.




