Skip to main content
WhyHow It WorksFeaturesPricingBlog
Sign inRequest demo

FedRAMP Definitions

67 defined terms (FRD). When a defined term appears in a FedRAMP rule, its definition is a critical part of that rule and must be followed precisely — even when the word is used differently elsewhere. Each term links to the rules and KSIs that reference it.

Accounts (2)

Assessment (2)

Certification (6)

Customer Effect (4)

Incident (5)

Information Resource (3)

Significant Changes (5)

Stakeholder (7)

FRD-ADV
Advisor

An entity that helps a provider understand, prepare for, or maintain FedRAMP Certification without replacing the provider's responsibility or the assessor's independence.

FRD-AGY
Agency

Has the meaning given in 44 U.S. Code § 3502 (1), which is "any executive department, military department, Government corporation, Government controlled corporation, or other establishment in the executive branch of the Government (including the Executive Office of the President), or any independent regulatory agency, but does not include—(A) the Government Accountability Office; (B) Federal Election Commission; (C) the governments of the District of Columbia and of the territories and possessions of the United States, and their various subdivisions; or (D) Government-owned contractor-operated facilities, including laboratories engaged in national defense research and production activities."

FRD-AAP
All Affected Parties

All federal entities whose interests are affected directly or are likely to be affected directly in the event of a vulnerability or incident related to federal customer data. This always includes FedRAMP and directly impacted federal customer agencies.

FRD-ANA
All Necessary Assessors

All entities who participate in the FedRAMP assessment of a cloud service offering in the context of a FedRAMP Certification. This always includes FedRAMP and any FedRAMP Recognized independent assessor contracted by a provider to perform a FedRAMP assessment.

FRD-ANP
All Necessary Parties

All entities whose interests are affected directly by activity related to a specific cloud service offering in the context of FedRAMP Certifications. This always includes FedRAMP and any agency customer who is using the cloud service offering, but may include additional parties depending on agreements made by the cloud service provider (such as consultants or independent assessors). Potential agency customers or third-party cloud service providers should also be included in most cases but this is not a mandatory requirement under FedRAMP because the cloud service provider may choose who they wish to do business with.

FRD-ASR
Assessor

An assessor that performs assessment, verification, or validation activities for a cloud service offering seeking to obtain or maintain FedRAMP Certification; FedRAMP is the final assessor for FedRAMP Certification, but FedRAMP Recognized independent assessment services are typically also utilized.

FRD-PRV
Provider

The cloud service provider responsible for a cloud service offering in the context of FedRAMP Certification.

Vulnerability (12)

FRD-ACV
Accepted Vulnerability

A vulnerability that the provider does not intend to fully mitigate or remediate, OR that has not or will not be fully mitigated or remediated within the maximum overdue period in FedRAMP Vulnerability Detection and Response rules.

FRD-FPV
False Positive Vulnerability

A detected vulnerability that is not actually present in an exploitable state in the information resource

FRD-FMV
Fully Mitigated Vulnerability

A vulnerability where the likelihood of exploitation or Potential Agency Impact N-rating has been reduced from the original evaluation until either are negligible, but the vulnerability is still detected.

FRD-IRV
Internet-Reachable Vulnerability (IRV)

A vulnerability in a machine-based information resource that might be exploited or otherwise triggered by a payload originating from a source on the public internet.

FRD-KEV
Known Exploited Vulnerability (KEV)

Has the meaning given in CISA Binding Operational Directive 22-01, which is any vulnerability identified in CISA's Known Exploited Vulnerabilities catalog.

FRD-LEV
Likely Exploitable Vulnerability (LEV)

A vulnerability that is not fully mitigated AND is reachable by a likely threat actor; AND a likely threat actor with knowledge of the vulnerability would likely gain unauthorized access, cause harm, disrupt operations, or otherwise have an undesired adverse impact within the cloud service offering by exploiting the vulnerability.

FRD-ODV
Overdue Vulnerability

A vulnerability that the provider intends to fully mitigate or remediate but has not or will not do so within the time frames recommended or required by FedRAMP.

FRD-PMV
Partially Mitigated Vulnerability

A vulnerability where the likelihood or Potential Agency Impact N-rating has been reduced from the original evaluation but the risk of exploitation still exists and the vulnerability is still detected.

FRD-RMV
Remediated Vulnerability

A vulnerability that has been neutralized or eliminated and is no longer detected.

FRD-VUL
Vulnerability

Has the meaning given to "security vulnerability" in 6 USC § 650 (25), which is "any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of [...] management, operational, and technical controls used to protect against an unauthorized effort to adversely affect the confidentiality, integrity, and availability of an information system or its information." This includes gaps in Rev5 controls and 20x Key Security Indicators, software vulnerabilities, misconfigurations, exposures, weak credentials, insecure services, and all other such potential weaknesses in protection (intentional or unintentional).

FRD-VLD
Vulnerability Detection

The systematic process of discovering and identifying security vulnerabilities in information resources through assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, supply chain monitoring, and other capabilities. This process includes the initial discovery of a vulnerability's existence and the determination of affected information resources within a cloud service offering.

FRD-VLR
Vulnerability Response

The systematic process of tracking, evaluating, mitigating, monitoring, remediating, assessing exploitation, reporting, and otherwise managing detected vulnerabilities.

Other (21)

FRD-CSO
Cloud Service Offering

A specific, packaged cloud computing product or service supplied by a cloud service provider for use by customers, that is the subject of a FedRAMP Certification.

FRD-DTM
Deterministic Telemetry

Verifiable data collected directly from an authoritative source that represents a factual and reproducible observation of the attributes of a system such as the system's state, configuration, or behavior.

FRD-DFT
Drift

Changes to information resources that cause deviations from the intended and assessed state; common forms of drift include changes to configurations, deployed software, privileges, running processes, and availability.

FRD-FCD
Federal Customer Data

All electronic information, content, and materials that an agency or its authorized users upload, store, or otherwise supply to a cloud service for processing or storage. This does NOT include account information, service metadata, analytics, telemetry, or other similar metadata generated by the cloud service provider.

FRD-FRA
FedRAMP Recognized

The status of independent assessment services that are recognized by FedRAMP to perform assessment activities on behalf of FedRAMP for cloud service offerings seeking to obtain or maintain FedRAMP Certification.

FRD-FSI
FedRAMP Security Inbox

An email address that follows the FedRAMP Security Inbox rules.

FRD-HAN
Handle

Has the plain language meaning inclusive of any possible action taken with information, such as access, collect, control, create, display, disclose, disseminate, dispose, maintain, manipulate, process, receive, review, store, transmit, use... etc.

FRD-LKY
Likely

A reasonable degree of probability based on context.

FRD-MGN
Machine-Generated

Automatically produced by a computer process, application, or other mechanism without the intervention or manipulation of a human during production.

FRD-MRD
Machine-Readable

Has the meaning from 44 U.S. Code § 3502 (18) which is "the term "machine-readable", when used with respect to data, means data in a format that can be easily processed by a computer without human intervention while ensuring no semantic meaning is lost"

FRD-ONC
Ongoing Certification

The continued FedRAMP Certification of a cloud service offering based on the applicable ongoing assessment, validation, monitoring, reporting, and certification data.

FRD-OCR
Ongoing Certification Report (OCR)

A regular report that is supplied by FedRAMP Certified cloud service providers to agency customers, following FedRAMP Collaborative Continuous Monitoring rules.

FRD-PER
Persistently

Occurring in a firm, steady way that is repeated over a long period of time in spite of obstacles or difficulties. Persistent activities may vary between actors, may occur irregularly, and may include interruptions or waiting periods between cycles. These attributes of persistent activities should be intentional, understood, and documented; the status of persistent activities will always be known.

FRD-PAI
Potential Agency Impact

The estimated cumulative effect of unauthorized access, disruption, harm, or other adverse impacts to all agencies using the cloud service that are likely to result from security incidents or the exploitation of vulnerabilities in the cloud service offering; as estimated following appropriate FedRAMP rules to calculate the Potential Agency Impact N-rating (PAIN).

FRD-PRO
Promptly

Without unnecessary delay.

FRD-RGL
Regularly

Performing the activity on a consistent, predictable, and repeated basis, at set intervals, automatically if possible, following a documented plan. These intervals may vary as appropriate between different activities.

FRD-RSP
Responsibly

In a way that shows that you have good judgment and the ability to act correctly and make decisions on your own.

FRD-SCT
Security Category

Has the meaning from NIST FIPS 199, which is "The characterization of information or an information system based on an assessment of the potential impact that a loss of confidentiality, integrity, or availability of such information or information system would have on organizational operations, organizational assets, or individuals." Security categories are often referred to as "impact levels" and include Low, Moderate, and High.

FRD-TRC
Trust Center

A secure repository or service used by cloud service providers to store and share FedRAMP Certification Data. Trust centers are the complete and definitive source for FedRAMP Certification Data and must follow the FedRAMP Certification Data Sharing rules to be FedRAMP-compatible.

FRD-VLN
Validation

Confirmation through objective evidence that implemented security capabilities and related certification data are suitable for their intended FedRAMP Certification use and support the expected security outcomes for a cloud service offering.

FRD-VRF
Verification

Confirmation through objective evidence that specified FedRAMP rules, controls, indicators, or certification data requirements have been fulfilled for a cloud service offering.