FedRAMP is a program that enables cloud services providers (CSPs) to meet the security requirements embedded with FISMA and the NIST publications so that an agency may outsource with the confidence that its cloud provider partner is meeting those requirements.
We begin each project with your end goals in mind and to provide preparation for future key project activities. Effective communication and timely coordination of project planning activities are central to our methodology with our clients.
Core CSP Activities
Submit documentation and evidence key controls
Schellman 3PAO Activities
Schellman conducts an independent readiness assessment and issues a formal Readiness Assessment Report (RAR) per the FedRAMP Ready program guidelines.
Core CSP Activities
Develop and submit core security program documentation including the System Security Plan (SSP) and related policies and procedures to the Agency or JAB.
Schellman 3PAO Activities
Schellman performs readiness review of the SSP and supporting documentation.
While client is finalizing its SSP, Schellman begins to collaborative draft the security assessment plan.
Core CSP Activities
Stage 1: Review and approve SAP prior to submission to the Agency or JAB
Stage 2: Assist Schellman by providing any required documentation and testing evidence. Document any Plan of Action and Milestones (POA&M) generated from the assessment.
Schellman 3PAO Activities
Stage 1: Draft and submit the SAP to the Agency or JAB for approval.
Stage 2: Conduct testing of all in-scope controls, complete detailed control finding matrices, and issue SAR.
Core CSP Activities
Submit security assessment package.
Schellman 3PAO Activities
Provide clarification to the Agency or JAB and/or client as required to complete the authorization process.
Core CSP Activities
Conduct annual continuous monitoring activities as specified in the FedRAMP Annual Assessment Guidance.
Schellman 3PAO Activities
Conduct annual assessment of core controls as well as 1/3 of the remaining NIST control set along with review of POA&Ms and remediation. Conduct annual penetration testing and oversee scanning activities as required.
Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.
The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.
Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing:
Schellman complies with ISO/IEC 17020:2012 and is governed by the American Association of Laboratory Accreditation (A2LA) which accredits FedRAMP 3rd Party Assessment Organizations (3PAOs).