What can we actually inherit from an authorized IaaS provider?

When utilising an authorized IaaS provider under FedRAMP, organisations can inherit a substantial portion of foundational security controls. This primarily includes physical and environmental security, core network infrastructure, and hypervisor management. However, customers retain direct responsibility for application-layer security, data protection, operating system configuration, and user access management within their deployed environments. Inheritance streamlines compliance but does not absolve the customer of their specific security obligations.

Organisations leveraging a FedRAMP-authorised Infrastructure as a Service (IaaS) provider can inherit a significant number of security controls related to the underlying infrastructure. This typically encompasses physical and environmental security controls for data centres, such as access controls, power, cooling, and fire suppression systems. Additionally, controls pertaining to the core network infrastructure, including boundary protection, network segmentation at the provider's layer, and the security of the hypervisor and underlying compute, storage, and networking hardware, are often inherited. This inheritance is possible because the IaaS provider has already undergone a rigorous assessment and achieved a FedRAMP authorisation for these foundational controls, which are documented in their System Security Plan (SSP).

Despite substantial inheritance, customers maintain direct responsibility for a critical set of security controls within their deployed environments. These responsibilities include, but are not limited to, securing operating systems (e.g., patching, hardening, configuration management), managing applications deployed on the IaaS platform, implementing data encryption (both at rest and in transit), establishing and enforcing identity and access management for their users and resources, and conducting vulnerability scanning and penetration testing of their customer-managed assets. A common pitfall is assuming full inheritance, which can lead to significant gaps in the customer's own SSP and a failure to implement necessary controls, potentially resulting in audit findings and security vulnerabilities. The FedRAMP Shared Responsibility Matrix explicitly delineates these boundaries.

Sources

  • FedRAMP Shared Responsibility Matrix
  • FedRAMP Guide to Understanding SaaS, PaaS, and IaaS

Related