---
title: "FedRAMP Security Controls — Definition & Engineering Context"
description: "The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services."
canonical: https://erpstack.io/glossary/fedramp
markdown_url: https://erpstack.io/glossary/fedramp.md
publisher: ERPStack
---

# FedRAMP Security Controls

> **Definition:** The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

## In depth

FedRAMP authorization is mandatory for cloud vendors selling software solutions to US federal agencies. FedRAMP classifies cloud systems into low, moderate, and high impact levels, requiring detailed audits of data encryption, host configuration, and backup setups.

## How ERPStack applies this

We design GovCloud application layouts matching FedRAMP moderate and high requirements, implementing FIPS-compliant encryption keys and detailed access auditing.

## Related reading

- [FISMA Government Compliance](https://erpstack.io/glossary/fisma)
- [Zero-Trust Security](https://erpstack.io/glossary/zero-trust)
