Skip to content
Cyber Horizon
All frameworks

// US Standards

FedRAMP Compliance Software

US government cloud security authorisation framework.

Framework at a glance

Short name

FedRAMP

Version

Category

US Standards

Controls

40

What FedRAMP covers

40 controls across 35 domains — every one tracked, owned and evidenced in Cyber Horizon.

Policy

1 controls
  • AC-1 Access Control Policy

Identity & Access

3 controls
  • AC-2 FedRAMP Account Management
  • AC-6 Least Privilege
  • IA-2(1) MFA — Privileged Accounts

Access Control

1 controls
  • AC-3 Access Enforcement

Remote Access

1 controls
  • AC-17 Remote Access

Logging

3 controls
  • AU-2 Event Logging
  • AU-3 Audit Record Content
  • AU-6 Audit Review and Reporting

Log Integrity

1 controls
  • AU-9 Protection of Audit Information

Assessment

1 controls
  • CA-2 Security Assessments

Network Security

1 controls
  • CA-3 System Interconnections

Monitoring

2 controls
  • CA-7 Continuous Monitoring
  • PE-6 Monitoring Physical Access

Baseline

1 controls
  • CM-2 Baseline Configuration

Hardening

1 controls
  • CM-6 Configuration Settings

System Hardening

1 controls
  • CM-7 Least Functionality

Business Continuity

1 controls
  • CP-4 Contingency Plan Testing

Backup

1 controls
  • CP-9 System Backup

Recovery

1 controls
  • CP-10 System Recovery

Authentication

1 controls
  • IA-2 Identification & Authentication

Credentials

1 controls
  • IA-5 Authenticator Management

IR

1 controls
  • IR-4 Incident Handling

Tracking

1 controls
  • IR-5 Incident Monitoring

Operations

1 controls
  • IR-6 Incident Reporting

Remote Maintenance

1 controls
  • MA-4 Non-local Maintenance

Media

1 controls
  • MP-5 Media Transport

Physical Access

1 controls
  • PE-2 Physical Access Authorisations

Physical Security

1 controls
  • PE-3 Physical Access Control

Documentation

1 controls
  • PL-2 System Security Plan

People

1 controls
  • PL-4 Rules of Behaviour

HR

1 controls
  • PS-3 Personnel Screening

Risk Management

1 controls
  • RA-3 Risk Assessment

Vulnerability Management

1 controls
  • RA-5 Vulnerability Scanning

Supply Chain

1 controls
  • SA-9 External System Services

Network

1 controls
  • SC-7 Boundary Protection

Encryption

1 controls
  • SC-8 Transmission Confidentiality

Cryptography

1 controls
  • SC-12 Cryptographic Key Management

Data Management

1 controls
  • SC-28 Protection of Information at Rest

Integrity

1 controls
  • SI-7 Software and Firmware Integrity

How Cyber Horizon automates FedRAMP

Every FedRAMP control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is FedRAMP?

US government cloud security authorisation framework.

How many controls does FedRAMP have?

FedRAMP has 40 controls in Cyber Horizon's catalogue, organised across 35 domains.

How does Cyber Horizon help with FedRAMP?

Cyber Horizon maps FedRAMP into a shared control library alongside every other framework you run, so evidence collected once counts towards FedRAMP and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See FedRAMP mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of FedRAMP in Cyber Horizon.