healthcarereimagined

Envisioning healthcare for the 21st century

  • About
  • Economics

Office of Management and Budget Releases Draft Memorandum for Modernizing the Federal Risk and Authorization Management Program (FedRAMP)

Posted by timmreardon on 11/21/2023
Posted in: Uncategorized.

OCTOBER 27, 2023

OMB is requesting public comment on a new draft memorandum to strengthen and enhance the Federal Risk and Authorization Management Program (FedRAMP).

Historically, the Federal Government has spent significant resources on physical data centers, missing out on the flexibility, security and performance of commercial cloud infrastructure. In 2011, OMB created FedRAMP to address these issues, and since then FedRAMP has served as a process for evaluating the security of commercial cloud services that helps agencies safely incorporate these products into their work and better focus their resources.

FedRAMP has worked well for that purpose, but the FedRAMP framework was built for a smaller job at a simpler time, and today’s cloud challenges are different. In the last decade, the security environment has become more complex, and the diversity of cloud services has grown dramatically. There are now many thousands of cloud-based services that Federal agencies could use to serve the American people, including tools for enterprise collaboration, product development, and improving an enterprise’s own cybersecurity. While there are currently 318 authorized services in the FedRAMP Marketplace, the tools that agencies need to deliver on their missions are not always included there. 

To help FedRAMP adapt to the new cloud environment, today OMB is releasing draft FedRAMP guidancefor public comment. The proposed guidance, which would replace previous guidance[1] that established the FedRAMP Program more than 10 years ago, sets out a plan to scale FedRAMP, strengthen its approach to security review, and accelerate the secure adoption of cloud products and services in the Federal Government.  Development of the draft guidance is a key milestone in a broader effort to strengthen the FedRAMP program, building on the Administration’s recent efforts in partnering with Congress to pass the FedRAMP Authorization Act in 2022 and establishing the Federal Secure Cloud Advisory Committee.  FedRAMP provides significant value to Federal agencies and industry and must keep pace with the evolving cloud marketplace so that agencies can take advantage of the full breadth of cloud-based products and services. This will result in a reduced technology footprint for agencies to manage and more efficient and accessible government services for the American public.

OMB has previously engaged with FedRAMP stakeholders, including the Federal Secure Cloud Advisory Committee (FSCAC), during the development of the draft guidance and looks forward to getting further input from the public comment process.

“In order to design policy that works, it’s critical that we engage stakeholders,” said Clare Martorana, Federal Chief Information Officer. “We are taking a human-centered policy design approach and soliciting input to learn about how government and industry experience the FedRAMP process and how we could evolve the program to increase its use and drive greater impact.”    

The proposed guidance would define the scope of cloud products subject to FedRAMP, set requirements for agencies to use FedRAMP-authorized services, outline the responsibilities of the FedRAMP Board and the FedRAMP Program Management Office (PMO), and promote a transparent and consistent process for the issuance of security authorizations for cloud services. 

“The draft FedRAMP guidance builds on the Administration’s priorities and principles outlined in Executive Order 14028, Improving the Nation’s Cybersecurity and the President’s National Cybersecurity Strategy,” said Chris DeRusha, Federal Chief Information Security Officer and Deputy National Cyber Director for Federal Cybersecurity. “This White House is committed to modernizing and strengthening government’s cybersecurity practices and posture.” 

Key areas of the draft guidance address how the FedRAMP Program would:   

  • Become more responsive to the risk profiles of individual services, as well as evolving risks throughout the cyber environment. 
  • Increase the quantity of products and services receiving FedRAMP authorizations by bringing agencies together to evaluate the security of cloud offerings and strongly incentivizing reuse of one FedRAMP authorization by multiple agencies.
  • Streamline the authorization process by automating appropriate portions of security evaluations, consistent with industry best practices.
  • Improve sharing of information with the private sector, including about emerging threats and best practices.

“FedRAMP was created to safeguard the cloud services relied upon by the Federal Government and to enable us to better deliver critical public services,” said Kemba Walden, Acting National Cyber Director. “This Administration has been clear through both Executive Order 14028 and the National Cybersecurity Strategy that the Federal Government must lead the way in improving the nation’s cybersecurity posture.  Over the next 30 days, we welcome feedback on how we can improve this vital program and drive better cybersecurity and innovation across the Federal Government.”


OMB is soliciting public comment on the draft guidance until November 27, 2023. To submit a public comment, visit https://www.regulations.gov/document/OMB-2023-0021-0001

Article link: https://www.whitehouse.gov/omb/briefing-room/2023/10/27/office-of-management-and-budget-releases-draft-memorandum-for-modernizing-the-federal-risk-and-authorization-management-program-fedramp/#

Share this:

  • Click to share on X (Opens in new window) X
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on LinkedIn (Opens in new window) LinkedIn
Like Loading...

Related

Posts navigation

← Mainstreaming universal health, with Japan at the helm as a long-lived nation – WEF
Research reveals rare metal could offer revolutionary switch for future quantum devices – Phys.org →
  • Search site

  • Follow healthcarereimagined on WordPress.com
  • Recent Posts

    • Hype Correction – MIT Technology Review 12/15/2025
    • Semantic Collapse – NeurIPS 2025 12/12/2025
    • The arrhythmia of our current age – MIT Technology Review 12/11/2025
    • AI: The Metabolic Mirage 12/09/2025
    • When it all comes crashing down: The aftermath of the AI boom – Bulletin of the Atomic Scientists 12/05/2025
    • Why Digital Transformation—And AI—Demands Systems Thinking – Forbes 12/02/2025
    • How artificial intelligence impacts the US labor market – MIT Sloan 12/01/2025
    • Will quantum computing be chemistry’s next AI? 12/01/2025
    • Ontology is having its moment. 11/28/2025
    • Disconnected Systems Lead to Disconnected Care 11/26/2025
  • Categories

    • Accountable Care Organizations
    • ACOs
    • AHRQ
    • American Board of Internal Medicine
    • Big Data
    • Blue Button
    • Board Certification
    • Cancer Treatment
    • Data Science
    • Digital Services Playbook
    • DoD
    • EHR Interoperability
    • EHR Usability
    • Emergency Medicine
    • FDA
    • FDASIA
    • GAO Reports
    • Genetic Data
    • Genetic Research
    • Genomic Data
    • Global Standards
    • Health Care Costs
    • Health Care Economics
    • Health IT adoption
    • Health Outcomes
    • Healthcare Delivery
    • Healthcare Informatics
    • Healthcare Outcomes
    • Healthcare Security
    • Helathcare Delivery
    • HHS
    • HIPAA
    • ICD-10
    • Innovation
    • Integrated Electronic Health Records
    • IT Acquisition
    • JASONS
    • Lab Report Access
    • Military Health System Reform
    • Mobile Health
    • Mobile Healthcare
    • National Health IT System
    • NSF
    • ONC Reports to Congress
    • Oncology
    • Open Data
    • Patient Centered Medical Home
    • Patient Portals
    • PCMH
    • Precision Medicine
    • Primary Care
    • Public Health
    • Quadruple Aim
    • Quality Measures
    • Rehab Medicine
    • TechFAR Handbook
    • Triple Aim
    • U.S. Air Force Medicine
    • U.S. Army
    • U.S. Army Medicine
    • U.S. Navy Medicine
    • U.S. Surgeon General
    • Uncategorized
    • Value-based Care
    • Veterans Affairs
    • Warrior Transistion Units
    • XPRIZE
  • Archives

    • December 2025 (8)
    • November 2025 (9)
    • October 2025 (10)
    • September 2025 (4)
    • August 2025 (7)
    • July 2025 (2)
    • June 2025 (9)
    • May 2025 (4)
    • April 2025 (11)
    • March 2025 (11)
    • February 2025 (10)
    • January 2025 (12)
    • December 2024 (12)
    • November 2024 (7)
    • October 2024 (5)
    • September 2024 (9)
    • August 2024 (10)
    • July 2024 (13)
    • June 2024 (18)
    • May 2024 (10)
    • April 2024 (19)
    • March 2024 (35)
    • February 2024 (23)
    • January 2024 (16)
    • December 2023 (22)
    • November 2023 (38)
    • October 2023 (24)
    • September 2023 (24)
    • August 2023 (34)
    • July 2023 (33)
    • June 2023 (30)
    • May 2023 (35)
    • April 2023 (30)
    • March 2023 (30)
    • February 2023 (15)
    • January 2023 (17)
    • December 2022 (10)
    • November 2022 (7)
    • October 2022 (22)
    • September 2022 (16)
    • August 2022 (33)
    • July 2022 (28)
    • June 2022 (42)
    • May 2022 (53)
    • April 2022 (35)
    • March 2022 (37)
    • February 2022 (21)
    • January 2022 (28)
    • December 2021 (23)
    • November 2021 (12)
    • October 2021 (10)
    • September 2021 (4)
    • August 2021 (4)
    • July 2021 (4)
    • May 2021 (3)
    • April 2021 (1)
    • March 2021 (2)
    • February 2021 (1)
    • January 2021 (4)
    • December 2020 (7)
    • November 2020 (2)
    • October 2020 (4)
    • September 2020 (7)
    • August 2020 (11)
    • July 2020 (3)
    • June 2020 (5)
    • April 2020 (3)
    • March 2020 (1)
    • February 2020 (1)
    • January 2020 (2)
    • December 2019 (2)
    • November 2019 (1)
    • September 2019 (4)
    • August 2019 (3)
    • July 2019 (5)
    • June 2019 (10)
    • May 2019 (8)
    • April 2019 (6)
    • March 2019 (7)
    • February 2019 (17)
    • January 2019 (14)
    • December 2018 (10)
    • November 2018 (20)
    • October 2018 (14)
    • September 2018 (27)
    • August 2018 (19)
    • July 2018 (16)
    • June 2018 (18)
    • May 2018 (28)
    • April 2018 (3)
    • March 2018 (11)
    • February 2018 (5)
    • January 2018 (10)
    • December 2017 (20)
    • November 2017 (30)
    • October 2017 (33)
    • September 2017 (11)
    • August 2017 (13)
    • July 2017 (9)
    • June 2017 (8)
    • May 2017 (9)
    • April 2017 (4)
    • March 2017 (12)
    • December 2016 (3)
    • September 2016 (4)
    • August 2016 (1)
    • July 2016 (7)
    • June 2016 (7)
    • April 2016 (4)
    • March 2016 (7)
    • February 2016 (1)
    • January 2016 (3)
    • November 2015 (3)
    • October 2015 (2)
    • September 2015 (9)
    • August 2015 (6)
    • June 2015 (5)
    • May 2015 (6)
    • April 2015 (3)
    • March 2015 (16)
    • February 2015 (10)
    • January 2015 (16)
    • December 2014 (9)
    • November 2014 (7)
    • October 2014 (21)
    • September 2014 (8)
    • August 2014 (9)
    • July 2014 (7)
    • June 2014 (5)
    • May 2014 (8)
    • April 2014 (19)
    • March 2014 (8)
    • February 2014 (9)
    • January 2014 (31)
    • December 2013 (23)
    • November 2013 (48)
    • October 2013 (25)
  • Tags

    Business Defense Department Department of Veterans Affairs EHealth EHR Electronic health record Food and Drug Administration Health Health informatics Health Information Exchange Health information technology Health system HIE Hospital IBM Mayo Clinic Medicare Medicine Military Health System Patient Patient portal Patient Protection and Affordable Care Act United States United States Department of Defense United States Department of Veterans Affairs
  • Upcoming Events

Blog at WordPress.com.
  • Reblog
  • Subscribe Subscribed
    • healthcarereimagined
    • Join 154 other subscribers
    • Already have a WordPress.com account? Log in now.
    • healthcarereimagined
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • View post in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...
 

    %d