惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
D
DataBreaches.Net
罗磊的独立博客
博客园 - 司徒正美
Last Week in AI
Last Week in AI
The Cloudflare Blog
大猫的无限游戏
大猫的无限游戏
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
The GitHub Blog
The GitHub Blog
宝玉的分享
宝玉的分享
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
小众软件
小众软件
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Hugging Face - Blog
Hugging Face - Blog
B
Blog
博客园 - 【当耐特】
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
酷 壳 – CoolShell
酷 壳 – CoolShell

MeriTalk

Eliminating Silos in IT/OT Cybersecurity Is a Funding Challenge, Not a Technical One The FedRAMP High Supply Crisis Is a Federal Security Problem – Not a Procurement Footnote How More Tightly Focused Software Development Initiatives Will Unlock Innovation Across Government Transforming Federal Cybersecurity Through Private Sector Innovation Evolving Zero Trust and Embedded AI – Federal Government Cybersecurity Predictions for 2026 Unlocking AI’s Potential in High-Assurance Environments Accelerate Agentic AI in the Federal Government: Top Takeaways Why Congress Must Reauthorize the Technology Modernization Fund Make Cybersecurity a Key Ingredient of Modernization How Spectro Cloud’s PaletteAI Secure helps agencies scale AI securely, compliantly, and confidently Fix the Foundation: How Hybrid Cloud and Trusted Data Enable Government AI New Google Workspace Cost-Saving Offer Available for U.S. Federal Government Balancing Security and Efficiency: The Federal IT Dilemma in the AI Era Meeting Evolving State and Local Cyber Threats AI Is the Solution to Stop AI Data Theft Enhancing U.S. Government Operations with AI and Human-Centered Design How FinOps Can Help Agencies Slash Cloud Costs in 5 Steps Will Quantum Computing Weaken or Strengthen Cybersecurity of Federal Systems? Improving Citizen and Federal Employee Experience with Virtual AI Assistants Strategies for Securing the Federal Supply Chain Reframing the U.S. Government’s Approach to Cybersecurity Oversight Three Steps Agencies Can Take to Meet Government’s AI Requirements The Impact of NIST’s PQC Standardization on the Federal Cybersecurity Ecosystem Generative AI is Revolutionizing Federal Government Operations NIST’s new PQC Algorithms and What They Mean for Federal Agencies Addressing the U.S. Quantum Labor Shortage Before It’s Too Late How a Community Vigil Approach and Secure by Design are Critical to Software Cybersecurity Addressing the Talent Shortage: How Digital Government Improves Satisfaction, Retention Here’s What We Can Learn (and Do) About Cybercrime from FBI’s Latest Internet Crime Report Implementing AI Assurance Safeguards Before OMB’s December Deadline
Reinventing FedRAMP in the Age of AI
MeriTalk Sta · 2025-06-09 · via MeriTalk

By David Appel, Vice President of U.S. Federal at AWS

For more than a decade, Amazon Web Services (AWS) has been at the forefront of enabling government agencies and their partners to deploy secure cloud services through the Federal Risk and Authorization Management Program, known as FedRAMP. This program provides a standardized compliance approach to U.S. federal government agencies as they adopt secure cloud solutions. AWS was the first cloud provider to achieve FedRAMP High authorization, and we supported Congress in codifying the FedRAMP program into law in 2022. Today, AWS has over 130 approved services at the High baseline and over 150 at Moderate.

The General Services Administration (GSA) recently announced FedRAMP 20x, a new compliance model aimed at modernizing the program through updated security practices. Over the past few months, experts from across AWS participated in industry working groups with other cloud providers, security experts, and agency representatives to share best practices and help shape implementation standards.

As GSA and federal IT security leaders continue reforming the program, they should consider the following recommendations:

Automate everything that can be automated. We are pleased to see GSA aim to automate compliance procedures everywhere possible. AWS is architected to be the most secure and flexible cloud environment available today. Our services already meet the rigorous security requirements set by FedRAMP, enabling our U.S. federal customers and our extensive partner network to confidently deploy cloud for mission-critical operations. By emphasizing real-time compliance verification and automated control validation, AWS can continue to be a strong partner to our government customers in continuing to deliver solutions at scale with the highest security standards.

Enable startups and new innovation. AWS supports FedRAMP 20x’s direction toward modernizing cloud security authorization, particularly through the initiative to recognize existing frameworks, which we believe will accelerate adoption for startups and AI providers. By acknowledging certifications like SOC 2 Type II, which already validates controls for security, availability, and confidentiality over an extended period, providers can leverage these existing assessments toward FedRAMP authorization. This approach eliminates redundant documentation, creates a more efficient path to authorization, and lowers barrier to entry for innovative cloud solutions while maintaining rigorous security standards.

Authorize secure, innovative AI. The use of AI, including Generative AI, is becoming an increasingly important tool that can help the government do more with less, thereby increasing the efficiency of service delivery to citizens while keeping cybersecurity a top priority. Through FedRAMP’s new proposed notification-based approach for significant changes, we believe that cloud providers will be able to rapidly deploy AI updates and improvements without lengthy approval processes. By significantly reducing compliance times for software services, these changes can help the federal government adopt AI solutions faster and tap into cutting-edge AI and machine learning tools for mission use. And by doubling down on proposed reforms, FedRAMP can help close the gap between a commercially deployed solution and one that is available for government use.

We believe the changes proposed by GSA, if implemented, could benefit both government and the citizens it serves. FedRAMP can further enable federal agencies to meet compliance requirements and enhance their security while realizing cost savings and greater speed and efficiencies.

We look forward to working with GSA to continue this momentum. We have been supporters of the program since its inception, and we are excited to be part of its future. By continuing to enhance FedRAMP’s security while expanding its offerings to our partners and government, we can continue to power the next generation of government innovation.