FedRAMP currently has two active community working groups that are open entirely to the public. These working groups interact in public on GitHub Discussions with bi-weekly summary recap sessions hosted on Zoom by FedRAMP.
- FedRAMP 20x: Focuses on exploring how FedRAMP can rely on automated validations to the greatest extent possible, and simply documentation and management requirements by relying on existing best practices and commercial security frameworks.
- FedRAMP Rev5: Focuses on grounding all Rev5 authorization and monitoring processes in modern security practices; revising and modifying the existing approach to enable commercial cloud providers to better deliver their services to the government.
FedRAMP is entirely focused on ensuring all stakeholders have equal and fair access to information as FedRAMP changes by addressing questions transparently in these community working groups - FedRAMP does not provide special answers to individual parties in private.
Additional Background
As a government program, FedRAMP has significant limitations on its ability to interact with the public compared to a typical private sector entity. For example, FedRAMP cannot ask for consensus opinions from the public, collect detailed structured feedback, provide business advice, or direct work. FedRAMP’s standard disclaimers apply to all content provided by FedRAMP staff in the community working groups.
The primary goals of the community working groups are:
-
Ensure FedRAMP has direct insight into community activities, goals, achievements, best practices, etc. in specific areas to inform creation of standards and policies prior to their formal development.
-
Ensure that FedRAMP stakeholders have equal public access to information from FedRAMP and an open forum and semi-structured opportunities to work towards shared goals in different and innovative ways.
Participation
- The majority of engagement will take place on GitHub Discussions
- Bi-weekly meetings hosted by FedRAMP will recap community working group activity and occasionally host Q&A, demos, or panel discussions
- All bi-weekly meetings will be recorded and shared on FedRAMP’s YouTube channel