Need help with Zapier?
Connect with an Expert

FedRAMP Seeks Industry Collaboration for New Cloud Security Approach

Industry Engagement for Transformation

In a recent address, Pete Waterman, director of the Federal Risk Authorization Management Program (FedRAMP) at the General Services Administration (GSA), emphasized the importance of industry involvement in transforming the cloud security program. During an event sponsored by the Alliance for Digital Innovation, Waterman stated, “We’re going to transform FedRAMP: Instead of the government deciding what is best, we’ll collaborate with industry to drive the solution.”

  • Waterman highlighted the need for continuous updates and collaboration within the FedRAMP community.
  • The goal is to move beyond outdated processes and embrace innovations within the industry.

New Approaches to Security Assessment

The initiative, referred to as FedRAMP 2025, marks a significant shift from the traditional management of the program over the past 12 years. Waterman explained that due to a leaner program management office with fewer resources, the GSA aims to establish policies and standards rather than act as a centralized authority.

  • The updated approach will focus on continuous validation and automation of security controls.
  • Waterman encourages third-party compliance tool vendors to contribute innovative solutions to the FedRAMP ecosystem.

Creating a Collaborative Community

To facilitate this collaboration, four community working groups will be established, focusing on various aspects of cloud security. Waterman clarified that these groups will not serve as advisory boards but rather as platforms for open discussion and collaboration among stakeholders.

  • The first meeting for the continuous monitoring working group is scheduled for March 31.
  • Subsequent meetings will cover automating assessments, applying existing frameworks, and continuous reporting.

A Vision for the Future

Waterman expressed optimism about automating validation processes to streamline security assessments. He highlighted the importance of modernizing FedRAMP to meet the needs of evolving technologies, stating, “It’s that simple and that complex, but this should be our goal.”

The PMO plans to leverage platforms like GitHub to keep the community informed and engaged as they work together towards establishing more effective standards in cloud security.