FedRAMP Tailored & LI-SaaS | Requirements and Impact Levels
Blog post from Box
FedRAMP Tailored, introduced in August 2017, is a streamlined process designed to expedite the adoption of cloud services for low-risk use cases by minimizing the number of required security controls. This program specifically targets Low-Impact Software-as-a-Service (LI-SaaS), which demands compliance with a subset of the Low Impact baseline's 125 security controls, focusing only on the most relevant requirements. It allows vendors to leverage existing FedRAMP Authorized products to inherit security controls, making it easier and more cost-effective to achieve authorization. LI-SaaS is intended for applications that pose minimal risk to federal agencies if compromised and must not contain personally identifiable information beyond basic login credentials. The program offers a quicker pathway for vendors to enter the federal market by allowing them to first obtain LI-SaaS authorization as a stepping stone to higher levels of authorization. However, it is only suitable for low-risk applications, and the traditional FedRAMP process remains necessary for systems requiring Moderate or High impact categorizations. Since its inception, nearly 30 LI-SaaS FedRAMP Authorized applications have been launched, highlighting the program's potential to accelerate cloud adoption in the federal sector.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.