FedRAMPGovernmentUnited StatesGovernment & Cloud Providers

Federal Risk and Authorization Management Program

U.S. government program providing standardized security assessment for cloud products serving federal agencies. Mandatory for cloud service providers working with federal government.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

FedRAMPAU-2A record of access

Audit Events

Organization MUST determine auditable events and ensure the system generates audit records for defined events.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

FedRAMPAU-3A record of access

Content of Audit Records

Audit records MUST contain: what type of event, when it occurred, where it occurred, source, outcome, and identity of individuals/subjects.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

FedRAMPAU-6Spotting the abnormalA record of access

Audit Review, Analysis, and Reporting

Organization MUST review and analyze audit records for indications of inappropriate or unusual activity.

Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.

FedRAMPAU-9Answering for an individual

Protection of Audit Information

System MUST protect audit information and audit tools from unauthorized access, modification, and deletion.

Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.

What FedRAMP covers

This instrument defines no data category of its own. Scope is set by the FIPS 199 IMPACT LEVEL of the system — low, moderate or high — which is derived from the consequence of compromise rather than from any data definition of its own.

How FedRAMP is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The FedRAMP PMO and the authorising agency.

FedRAMP has no penalty schedule because it does not need one. Unresolved items on a corrective action plan escalate from the plan itself to suspension to permanent revocation, and a revoked system re-enters the authorisation process from the beginning. There is no expedited path back.

Misrepresenting FedRAMP status in a federal contract is a separate matter, and is pursued under the False Claims Act rather than under FedRAMP.

Uncapped exposure that sits outside this instrument

These come from company law rather than from FedRAMP, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for FedRAMP,
not configured for it afterwards

Policy Template

NIST 800-53 AU Family

Complete implementation of all AU (Audit) controls

Report

FedRAMP Evidence Package

Pre-formatted evidence for 3PAO assessments

Classification

CUI Patterns

Detect Controlled Unclassified Information categories

Alert

Audit System Health

Monitor and alert on audit logging system availability

Walk into the FedRAMP audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment