FedRAMP Authorization Act on Definitions¶
Delegation of Authority to the FedRAMP Director
The GSA Administrator's authority and responsibility for Sec. 3607 - 3616 has been delegated to the FedRAMP Director; therefore any mention of the Administrator in these materials can also be read as the FedRAMP Director.
The Director in the law is not the FedRAMP Director!
The Director in this section of law is the Director of the Office of Management and Budget - not the FedRAMP Director. The authority and responsibility for the Director
has been delegated to the Federal Chief Information Officer.
Sec. 3607. Definitions¶
(a) In General¶
Except as provided under subsection (b), the definitions under sections 3502 and 3552 apply to this section through section 3616.
(b) Additional Definitions¶
In this section through section 3616:
-
AdministratorThe term
Administratormeans the Administrator of General Services. -
Appropriate congressional committeesThe term
appropriate congressional committeesmeans the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives. -
Authorization to operate; federal informationThe terms
authorization to operateandFederal informationhave the meaning given those term in Circular A-130 of the Office of Management and Budget entitledManaging Information as a Strategic Resource, or any successor document. -
Cloud computingThe term
cloud computinghas the meaning given the term in Special Publication 800-145 of the National Institute of Standards and Technology, or any successor document. -
Cloud service providerThe term
cloud service providermeans an entity offering cloud computing products or services to agencies. -
FedRAMPThe term
FedRAMPmeans the Federal Risk and Authorization Management Program established under section 3608. -
FedRAMP authorizationThe term
FedRAMP authorizationmeans a certification that a cloud computing product or service has---
A. completed a FedRAMP authorization process, as determined by the Administrator; or
B. received a FedRAMP provisional authorization to operate, as determined by the FedRAMP Board.
-
FedRAMP authorization packageThe term
FedRAMP authorization packagemeans the essential information that can be used by an agency to determine whether to authorize the operation of an information system or the use of a designated set of common controls for all cloud computing products and services authorized by FedRAMP. -
FedRAMP boardThe term
FedRAMP Boardmeans the board established under section 3610. -
Independent assessment serviceThe term
independent assessment servicemeans a third-party organization accredited by the Administrator to undertake conformity assessments of cloud service providers and the products or services of cloud service providers. -
SecretaryThe term
Secretarymeans the Secretary of Homeland Security.