Skip to main content
Compliance & Regulation

FedRAMP Security Controls

Term 40 of 68 in the ERPStack technical glossary

What is FedRAMP Security Controls?

The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

FedRAMP Security Controls at a glance

Basis
NIST SP 800-53 Rev. 5 controls, finalised 23 September 2020, applied to cloud services
Baselines
3 impact baselines — low, moderate and high — with control counts rising accordingly
Reuse model
1 authorisation package, many agencies — the point is to avoid N separate assessments
Practical constraint
Your service inherits controls only from cloud services already authorised at your baseline
Built with
Workloads on AWS or Microsoft Azure defined in Terraform, RBAC and SSO in Next.js 16, PostgreSQL 18 encrypted at rest, changes gated by GitHub Actions, monitored through Sentry
Numbers that matter
3 baselines from NIST SP 800-53 Rev. 5; 1 authorisation package reused by N agencies; ERPStack holds 0 authorisations; 0 controls inherited from unauthorised infrastructure
Adjacent regimes
FISMA Government Compliance, SOC 2 and ISO 27001
Commonly paired with
AWS or Microsoft Azure authorised services, Terraform, GitHub Actions change control, Docker workloads, RBAC, SSO and Sentry monitoring
Who it applies to
government agencies buying a cloud service. Adjacent healthcare and finance estates reuse the same NIST SP 800-53 Rev. 5 control language without the authorisation.

How FedRAMP Security Controls works in production

FedRAMP authorization is mandatory for cloud vendors selling software solutions to US federal agencies. FedRAMP classifies cloud systems into low, moderate, and high impact levels, requiring detailed audits of data encryption, host configuration, and backup setups.

The ERPStack approach to FedRAMP Security Controls

We design GovCloud application layouts matching FedRAMP moderate and high requirements, implementing FIPS-compliant encryption keys and detailed access auditing.

Frequently asked questions about FedRAMP Security Controls

What are FedRAMP Security Controls based on?

The NIST SP 800-53 Rev. 5 catalogue, finalised on 23 September 2020, tailored into baselines for cloud services. Security Controls are grouped into low, moderate and high impact baselines, and a service is assessed against the baseline matching the sensitivity of the data it will hold. The framework exists so that 1 rigorous assessment can be reused by many agencies rather than repeated.

What does control inheritance mean?

That some Security Controls are satisfied by the platform beneath you rather than by your own code. A service running on an already-authorised infrastructure provider inherits physical, environmental and parts of the network control set, and documents the rest itself. This is why the hosting choice is effectively a compliance decision: building on infrastructure without authorisation at your baseline means inheriting nothing.

Is FedRAMP relevant outside government?

As a benchmark, often. The Security Controls describe encryption, access management, logging, vulnerability management and incident response at a level of rigour many commercial buyers now expect. Designing to them is defensible even without pursuing authorisation — provided nobody describes the result as authorised, which is a specific status granted through a formal process rather than a design property.

How should a build be structured for this?

So that evidence is a by-product. Security Controls covering configuration management, change control and monitoring are satisfied far more easily when infrastructure is defined in Terraform, changes arrive through reviewed pull requests, and logs are centralised and immutable. ERPStack builds to that shape and holds no authorisation itself; the authorisation belongs to the service operator and its assessor.

Related reading

Explore Custom ERP Solutions by Location, Industry, and Alternatives

Global Architectures