FedRAMP
Federal Risk and Authorization Management Program. The US government cloud services authorization framework. Levels: Low, Moderate, High. Required for SaaS used by federal agencies. Authorization timelines run 12-24 months.
FedRAMP is a market gate more than a security ceiling: it determines which identity vendors a federal agency can buy at all, which is why the authorized list is much shorter than the vendor landscape. Authorization timelines measured in months to years also shape the product, because vendors freeze the authorized boundary and ship new capability outside it. Check what is actually in the boundary, not just that the vendor holds an authorization.
See also: compliance guides, SOC 2, NIST 800-63, identity for government article
Related on Start with Identity
- GlossaryAML
Anti-Money Laundering. The set of regulations and processes used to detect and report suspicious financial activity. AML programs sit on top of KYC and include
- GuideCustomer Identity Verification Guide: KYC, Document Verification, and Fraud Prevention
Implement customer identity verification with KYC processes, document verification, liveness detection, progressive profiling, and fraud prevention strategies.
- GlossaryGDPR
General Data Protection Regulation. EU privacy law in force since 2018. Establishes user rights (access, rectification, erasure, portability) and obligations on
- GuideGDPR for identity systems: what the regulation actually requires
GDPR confers user rights (access, rectification, erasure, portability, object). Identity systems are usually where those requests are routed because they hold t
- GlossaryHIPAA
Health Insurance Portability and Accountability Act. US law governing the privacy and security of protected health information. Identity vendors serving healthc
- GuideIAM Audit Preparation Guide: SOX, SOC 2, and HIPAA Readiness
Prepare for identity and access management audits with complete evidence collection, access review documentation, and compliance frameworks for SOX, SOC 2, and