Control frameworkCompliance & AuditHigh baseline scope

FedRAMP High policy template

Review this template's scope and control areas. Then, open it in the Verdictan console to adapt and test the configuration for your environment.

Map federal cloud workloads to the FedRAMP Revision 5 High baseline. The template covers relevant access, audit, encryption and configuration topics. Media, physical, assessment and authorization controls remain outside the gateway. The template does not provide a FedRAMP authorization.

Use this template as a starting configuration and control map. It does not provide certification, legal advice or a compliance guarantee. Confirm your obligations, adapt the configuration and test every outcome before deployment.

Regions

US

Source references

4 source references

Control areas

8 mapped control areas

Deployment options

Sovereign region, Fully air-gapped

Source frameworks, standards and obligations

FedRAMP Authorization Act (44 U.S.C. §§ 3607-3616)FedRAMP Rev. 5 High BaselineNIST SP 800-53 Rev. 5NIST SP 800-53B

Control areas mapped by this template

Access control
Audit logging
Incident response
Data encryption
Vulnerability management
Configuration management
Media protection
Physical security

Deployment options

Sovereign region
Fully air-gapped

Adapt the template in three steps

1

Review the scope

Confirm that the regions, source references, control areas and deployment options fit your use case.

2

Adapt the configuration

Open the template in the Verdictan console. Set its policies, thresholds, routing and review requirements for your environment.

3

Test before deployment

Test each policy outcome. Confirm that allowed, redacted, blocked and reviewed requests behave as expected.