Token导航 LogoToken导航TokenDH.com
研究检索external-servicegithub未标认证来源可访问许可证需确认审计通过

fedrampfedramp 搜索

Agent Skill

fedramp 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

40

周安装

17

GitHub Stars

352

下载量

140
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:fedramp(fedramp 搜索)
来源仓库:https://github.com/sushegaad/claude-skills-governance-risk-and-compliance
仓库路径:skills/fedramp
安装命令:
npx skills add https://github.com/sushegaad/claude-skills-governance-risk-and-compliance --skill fedramp
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/sushegaad/claude-skills-governance-risk-and-compliance --skill fedramp

简介

fedramp 提供 FedRAMP 认证全流程指导,涵盖准备、ATO 文档和控制映射。

  • 适用于 Codex、Claude、Cursor、Gemini CLI,适合云服务提供商满足政府合规要求时使用。
  • 支持差距评估、SSP/POA&M 编写、控制实施和持续监控全周期管理。
  • 安装前需确认权限范围和维护状态,注意涉及敏感配置时需谨慎操作。
  • fedramp 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

FedRAMP Certification Skill

A comprehensive guide for helping users navigate FedRAMP authorization — from initial readiness through ATO and ongoing continuous monitoring.

Quick Reference: What Does the User Need?

Identify the user's goal and jump to the appropriate section:

User GoalGo To
"Are we ready for FedRAMP?" / gap assessmentReadiness & Gap Assessment
Writing SSP, POA&M, SAR, SAP, or other docsATO Documentation
"Which controls apply to us?" / control mappingNIST 800-53 Control Mapping
Cloud architecture / AWS/Azure/GCP configArchitecture Guidance
Already authorized, ongoing complianceContinuous Monitoring

Current FedRAMP State (as of 2025–2026)

  • Baseline: NIST SP 800-53 Rev 5 (approved May 2023, fully in effect)
  • Control counts (Rev 5): Low = ~156, Moderate = 323, High = 421
  • OSCAL mandate: RFC-0024 requires all CSPs to transition to machine-readable OSCAL packages by September 2026
  • Security Inbox: As of January 5, 2026, all authorized CSPs must maintain a dedicated Security Inbox for urgent vulnerability directives (no CAPTCHAs or barriers)
  • FedRAMP 20x: A modernization initiative in progress; introduces continuous authorization and modular/API-driven submissions. Traditional SSP/SAP/SAR templates remain required for non-20x paths.
  • Key templates updated: SSP, SAR, SAP, POA&M, CIS/CRM, IIW, ISCP — all updated to align with Rev 5 (Dec 2024 releases)

1. Readiness & Gap Assessment

Approach

  1. Clarify scope — Ask the user: What is the CSO (Cloud Service Offering)? IaaS/PaaS/SaaS? Target impact level?
  2. Identify authorization path — Agency Authorization (sponsor needed) vs. JAB P-ATO (Joint Authorization Board — effectively suspended since 2024; verify current status with FedRAMP PMO) vs. FedRAMP 20x pilot
  3. Run through the readiness checklist — See references/readiness-checklist.md
  4. Surface gaps — Map current state to required controls; flag missing documentation, unimplemented controls, and architectural deficiencies
  5. Prioritize — Group gaps by: (a) blockers for readiness review, (b) items addressable before 3PAO assessment, (c) POA&M candidates

Key Readiness Questions to Ask the User

  • What cloud platform (AWS GovCloud, Azure Government, GCP, on-prem hybrid)?
  • Are you leveraging any existing FedRAMP-authorized IaaS/PaaS (e.g., AWS GovCloud FedRAMP High)?
  • Do you have FIPS 140-2/3 validated encryption in place?
  • Is your authorization boundary defined and documented?
  • Do you have a vulnerability scanning program (OS, DB, web app, container)?
  • Are security policies and procedures documented?
  • Do you have an Incident Response Plan (IRP) and Contingency Plan (CP) that have been tested?

Output Format

  • Produce a gap table: Control Family | Current State | Gap | Priority | Owner
  • Summarize top 5–10 high-priority gaps as prose
  • Recommend whether to pursue Readiness Assessment Report (RAR) first

2. ATO Documentation

The core FedRAMP authorization package consists of:

Authorization Package
├── System Security Plan (SSP) + Appendices A–Q
├── Security Assessment Plan (SAP) + Appendices A–D  [3PAO-prepared]
├── Security Assessment Report (SAR) + Appendices A–F  [3PAO-prepared]
└── Plan of Action & Milestones (POA&M)  [SSP Appendix O]
Important: CSPs must use official FedRAMP PMO templates. Reviewers are trained on standardized formats; non-standard submissions risk rejection or delays. Templates: https://www.fedramp.gov/rev5/documents-templates/

Document Guidance

For detailed guidance on each document type, read the appropriate reference file:

  • SSPreferences/ssp-guide.md
  • POA&Mreferences/poam-guide.md
  • SAP / SARreferences/sap-sar-guide.md
  • Supporting appendicesreferences/appendices-guide.md

General Writing Principles for All ATO Docs

  1. Describe only what is implemented — Do not document planned or aspirational controls; these trigger findings and must go in POA&M instead
  2. Be specific — Reference exact tools, filenames, section numbers, policy names; vague language causes findings
  3. Mind the verbs — Each control requirement uses specific verbs (track, document, enforce, test). Address each verb explicitly
  4. Shared responsibility — For any customer-configurable or shared control, create a clear "Customer Responsibility" section
  5. Keep it consistent — Architecture diagrams, data flows, inventory, and control statements must all be internally consistent

3. NIST 800-53 Control Mapping

Control Families (Rev 5)

IDFamilyNotes
ACAccess ControlIAM, RBAC, least privilege, remote access
ATAwareness & TrainingSecurity + privacy training (new in Rev 5)
AUAudit & AccountabilityLog retention, SIEM, audit review
CAAssessment, Authorization & MonitoringConMon, 3PAO, ATO
CMConfiguration ManagementBaselines, change control, CMDB
CPContingency PlanningBCP/DR, tested annually
IAIdentification & AuthenticationMFA, PIV, FIPS 140-2/3 crypto
IRIncident ResponseIRP, tested annually, reporting SLAs
MAMaintenanceRemote maintenance controls
MPMedia ProtectionData at rest, media sanitization
PEPhysical & EnvironmentalDatacenters; often inherited from IaaS
PLPlanningSSP, rules of behavior
PMProgram ManagementEnterprise-level security program
PSPersonnel SecurityScreening, termination procedures
PTPII Processing & TransparencyNew family in Rev 5 — privacy controls
RARisk AssessmentVulnerability scanning, MITRE ATT&CK scoring
SASystem & Services AcquisitionSDLC, supply chain
SCSystem & Communications ProtectionEncryption in transit, network segmentation
SISystem & Information IntegrityPatching, malware, integrity monitoring
SRSupply Chain Risk ManagementNew family in Rev 5 — SCRM

Impact Level Mapping

When the user describes their system, recommend the impact level:

  • LI-SaaS (Low-Impact SaaS): No PII, no sensitive federal data, limited scope — uses a simplified template combining SSP + assessment
  • Low: Federal information where loss of CIA has limited adverse effect
  • Moderate: Most common — federal information where loss has serious adverse effect; covers the majority of CSPs handling non-classified government data
  • High: Federal information where loss has severe or catastrophic effect (e.g., law enforcement, financial, health data)

Mapping Workflow

  1. Ask: What types of federal data will the system process/store/transmit?
  2. Run FIPS 199 categorization (Confidentiality / Integrity / Availability × Impact)
  3. Select baseline (Low/Moderate/High) based on high-water mark
  4. Cross-reference with FedRAMP parameter requirements (FedRAMP often sets stricter parameters than base NIST)
  5. For inherited controls, identify which are fully/partially inherited from leveraged FedRAMP IaaS/PaaS and document in CIS/CRM workbook

Rev 4 → Rev 5 Key Changes to Highlight

  • New control families: PT (Privacy), SR (Supply Chain)
  • Password controls revised: No more forced rotation schedules; now requires compromised-password lists and password strength meters (NIST 800-63b alignment)
  • Privacy integrated: AT-3 now mandates privacy training; many families have privacy-specific enhancements
  • Threat-based methodology: MITRE ATT&CK framework now informs control prioritization
  • Moved/merged controls: Some Rev 4 controls were merged — don't assume 1:1 mapping

4. Architecture Guidance

Authorization Boundary

The boundary defines what is IN scope for FedRAMP. This is one of the most common sources of findings and delays.

Key principles:

  • Everything that processes, stores, or transmits federal data must be inside the boundary
  • External services connected to in-scope systems must be FedRAMP-authorized OR documented with compensating controls
  • Boundary must be depicted in a clear network/data flow diagram (required in SSP)

Cloud Platform Considerations

AWS GovCloud (US)

  • AWS GovCloud is FedRAMP High authorized — most PE and some SC controls are fully inherited
  • Use AWS Config, CloudTrail, GuardDuty, Security Hub to satisfy AU, RA, SI controls
  • Ensure use of GovCloud region endpoints (not standard commercial) to stay in boundary
  • FIPS endpoints available for IA controls

Azure Government

  • Azure Government is FedRAMP High authorized
  • Azure Policy + Defender for Cloud maps well to CM, RA, SI
  • Use Azure Blueprints / Policy Initiatives aligned to FedRAMP Moderate/High

Google Cloud (FedRAMP-authorized regions)

  • Assured Workloads for FedRAMP compliance
  • Chronicle SIEM for AU controls

Architecture Patterns That Support FedRAMP

  • Zero Trust — aligns directly with AC, IA, SC control families
  • Immutable infrastructure — simplifies CM (configuration drift is a common finding)
  • Centralized logging — SIEM/log aggregation addresses AU family comprehensively
  • Automated vulnerability scanning — Required; must cover OS, DB, web app, and containers (if used)
  • Container security — FedRAMP has specific container scanning guidance; image signing and runtime protection are expected

Common Architecture Findings

  • Undocumented external connections leaving the boundary
  • FIPS-non-compliant encryption algorithms in transit or at rest
  • Overly broad IAM roles / lack of least privilege
  • Missing MFA on privileged accounts
  • Vulnerability scans not covering all boundary components
  • Logging gaps (not all components sending logs to centralized SIEM)

5. Continuous Monitoring

Once authorized, CSPs must maintain compliance through ConMon activities:

Monthly Requirements

  • Vulnerability scan results submitted to agency AOs
  • POA&M updates (open findings, remediation progress)
  • Inventory updates (new/removed assets)
  • ConMon Monthly Executive Summary (template updated Nov 2024)

Annual Requirements

  • Full security assessment by 3PAO using Annual Assessment Controls Selection Worksheet
  • Updated SSP and appendices
  • Tested IRP and CP
  • SAR and updated POA&M

POA&M Management

  • All open findings must have: risk level, owner, milestone dates, remediation plan
  • Vendor Dependencies (VDs): when a finding depends on a third-party fix — document and track
  • Deviation Requests (DRs): false positives and risk adjustments require AO approval
  • SLA for remediation: Critical = 30 days, High = 90 days, Moderate = 180 days, Low = 365 days (FedRAMP standard)

Output Formatting Guide

Match output format to request type:

Request TypePreferred Format
Gap assessmentTable + prose summary
SSP control narrativeProse paragraphs (one per control/enhancement)
POA&M entryStructured table row with all required fields
Architecture reviewBullet findings + recommended remediations
Control mapping questionTable: Control ID \Requirement \How to Implement
Readiness overviewExecutive summary prose + priority action list

When generating document content, always note: *"Use official FedRAMP templates from fedramp.gov — this content should be inserted into the appropriate template section."*


Reference Files

Load these when more depth is needed:

  • references/readiness-checklist.md — Full readiness checklist (75+ items)
  • references/ssp-guide.md — SSP section-by-section writing guide
  • references/poam-guide.md — POA&M structure, field definitions, SLA table
  • references/sap-sar-guide.md — SAP/SAR overview and review tips for CSPs
  • references/appendices-guide.md — Guide to all SSP appendices (A–Q)
  • references/control-families.md — Deep-dive on each of the 20 control families

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

39.15%
按下载量换算55

Claude

27.53%
按下载量换算39

Cursor

20.37%
按下载量换算29

Gemini CLI

9.71%
按下载量换算14

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills