What 44 USC § 3614 - Federal Risk and Authorization Management Program (FedRAMP) requires
44 USC § 3614 (enacted by the FedRAMP Authorization Act of 2022, Pub. L. 117-263 Title LIX) codifies the Federal Risk and Authorization Management Program (FedRAMP) as the government-wide standardized approach to security assessment, authorization, and continuous monitoring of cloud computing products and services used by federal agencies: subsection (a) directs the Director of OMB to issue guidance specifying categories or characteristics of cloud computing products and services within FedRAMP scope; subsection (b) establishes requirements for agencies to obtain FedRAMP authorization when operating cloud computing products or services; subsection (c) directs the OMB Director to oversee the effectiveness of FedRAMP and the FedRAMP Board (established at 44 USC 3610(d)); the program is administered by the General Services Administration (GSA) FedRAMP Program Management Office (PMO) and supported by the Joint Authorization Board (JAB - DoD, DHS, GSA) and individual agency authorizing officials; authorization types include FedRAMP Ready, FedRAMP Authorization to Operate at Low, Moderate, High, and LiSaaS impact levels per FIPS 199; the program incorporates NIST SP 800-53 Revision 5 security controls baseline; statute is scheduled to sunset 5 years after enactment (December 23, 2027) absent reauthorization.
Pillar: Cloud & SaaS · Authority: United States Congress (FedRAMP Authorization Act of 2022, Pub. L. 117-263, Title LIX, § 5921 - James M. Inhofe National Defense Authorization Act for Fiscal Year 2023; codified at 44 USC § 3614, enacted 23 December 2022) · Version: 1.0.0 · Last updated:
Primary source: https://www.law.cornell.edu/uscode/text/44/3614
SHA-256 integrity: 743bd75420d9283ec99bfef2587e7693a4351e04f14953505c52b9ba3702848f
Primary Citations — 5 traced to source
- 44 USC § 3614(a) OMB GUIDANCE ON FEDRAMP SCOPE: 'The Director shall issue guidance that (1) specifies the categories or characteristics of cloud computing products and services that are within the scope of FedRAMP; (2) establishes the requirements for agencies to obtain a FedRAMP authorization when operating a cloud computing product or service'
- 44 USC § 3614(b) AGENCY AUTHORIZATION REQUIREMENT: 'A Federal agency shall not operate a cloud computing product or service unless the cloud computing product or service has received a FedRAMP authorization' - with exceptions for specific national security systems and limited testing scenarios
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/us-44-usc-3614-fedramp-authorization-program.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/us-44-usc-3614-fedramp-authorization-program.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/us-44-usc-3614-fedramp-authorization-program
- Back to registry: Browse all 10,085 compliance nodes