Listing Thumbnail

    FedRAMP Assessment

     Info
    KirkpatrickPrice will perform an audit of the moderate baseline controls using the FedRAMP security controls baseline. This will be an important step to ready any organization for the FedRAMP certification process.

    Overview

    FedRAMP is a Federal Government program to standardize how the Federal Information Security Management Act (FISMA) applies to cloud computing services. The FedRAMP program provides a standardized approach to security assessment, authorization, and continuous monitoring of cloud based services.Leveraging FedRAMP compliant security controls native to AWS cloud infrastructure simplifies the path to Authorization.

    Federal Agencies are required to assess and authorize information systems in accordance with FISMA. The FedRAMP SAF is compliant with FISMA and is based on NIST Special Publication 800- 37. FedRAMP defines a set of controls for Low and Moderate security impact level systems based on NIST baseline controls (NIST SP 800-53, as revised) with a set of control enhancements that pertain to the unique security requirements of cloud computing.

    KirkpatrickPrice will perform an audit of the moderate baseline controls using the FedRAMP security controls baseline. The 20 control families comprising these controls are defined in FIPS Publication 200: Minimum Security Requirements for Federal Information and Information Systems and in NIST 800-53 r5, Security and Privacy Controls for Information Systems and Organizations.

    Scoping Exercise

    KirkpatrickPrice will perform a scoping exercise to help determine the authorization boundary. The authorization boundary establishes the clear demarcation between the system and its surrounding environment, including external systems , data sources, and users. Per FedRAMP requirements, this infrastructure information must be represented as a diagram, including the key components identified in this boundary description and any external dependencies. The flow of classified and unclassified data must also be documented as a diagram. The diagram will place heavy reliance on the services leveraged in the AWS GovCloud and our experts hold AWS certifications such as Certified Cloud Practitioner, Solution Architect, and the Security Specialization.

    System Security Plan

    In this phase, KirkpatrickPrice will assist clients with completing an initial SSP draft. We will review the various sections of the SSP and assist clients with providing appropriate information based on scope. We will also review Appendix A to assess current level of control implementation. As an AWS user, services like EC2, EKS, CloudTrail, etc. allow the cloud service provider to reduce risk and responsibility by relying on the security capabilities native to AWS.

    Remediation Support & Assistance through 3PAO Audit

    KirkpatrickPrice will assist clients in remediating gaps identified in Phase 2. KirkpatrickPrice will also partner with the clients team during the 3PAO process and continue to advise through the FedRAMP Ready assessment.

    FedRAMP Assessment & Authorization

    Overview

    KirkpatrickPrice will engage a 3PAO partner to conduct a FedRAMP 3PAO assessment of the client’s cloud service offering. The 3PAO partner will serve as the independent 3PAO, whereas KirkpatrickPrice will serve as an advisor/consultant to the client. The 3PAO partner will provide the following audit services in support of the FedRAMP 3PAO Assessment:

    • Conduct the FedRAMP Assessment in accordance with latest FedRAMP PMO guidance
      • Manual Control Testing
      • Vulnerability Scanning (Network/OS, AWS Infrastructure, Databases like RDS, and ECS/EKS Containers)
      • Penetration Testing (in accordance with defined FedRAMP attack paths)
    • Provide all respective FedRAMP documentation to the Authorizing Agency for review and finalization
    • FedRAMP Program/Meeting Support

    The scope of this assessment covers all 3PAO Partner-provided FedRAMP audit services in support of obtaining/maintaining a FedRAMP Authorization.

    KirkpatrickPrice will provide project management to align 3PAO partner resources for the FedRAMP assessment with KirkpatrickPrice resources conducting other audits. The Online Audit Manager will be the portal used for audit evidence collection.

    Highlights

    • KirkpatrickPrice has issued over 20,000 reports to 2,000 clients worldwide, giving them the assurance they deserve. By conducting every audit engagement with thorough, quality testing, KirkpatrickPrice delivers reports with results you can trust.
    • KirkpatrickPrice auditors have an average of 25+ years of experience and have worked in the field as CTOs, CISOs, CSOs, and more. They truly understand how hard an audit can be, and what makes them a valuable, worthwhile experience. Additionally, our refined audit delivery processes have been developed over 18 years to include SMEs, Client Success Managers, and Professional Report Writers.
    • The Online Audit Manager, the world’s first compliance platform, simplifies and streamlines your audit process by allowing you to prepare for and successfully complete an audit all in one place. The platform was developed by CPAs to help manage the audit process and connect you directly to an auditor throughout your compliance journey.

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Resources

    Vendor resources

    Support

    Vendor support

    When you work with KirkpatrickPrice on any of your compliance efforts, you’re gaining a partner who truly cares about helping you achieve your security and compliance goals. You’ll work with an expert auditor, but you’ll also partner with a team of experts dedicated to your success. Your audit engagement team includes a Client Success Manager, Professional Writer, Information Security Associate, and of course an experienced Information Security Auditor.

    Additionally, the Online Audit Manager connects you directly to an information security expert who will work alongside you in the platform. You are able to instantly initiate a live chat with an expert whenever a question arises that you need a quick answer to.

    For support request, connect with one of our experts by calling 800-770-2791 or visiting our website <www.kirkpatrickprice.com/contact/ > .