You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/data/pages/home.yaml
+8-11Lines changed: 8 additions & 11 deletions
Original file line number
Diff line number
Diff line change
@@ -64,20 +64,17 @@ stepsList:
64
64
text: "Launch your cloud services with a one-year renewable agreement designed for continuous adaptation. Months before you renew, we reach out to you about your evolving technology needs, ensuring your technology always matches your mission."
65
65
66
66
mandatesHandled:
67
-
heading: "2025 federal compliance mandates—platform controls handled for you"
67
+
heading: "The latest 2025 federal compliance mandates, handled"
68
68
art: "compliance-alt"
69
69
color: "primary-vivid"
70
70
intro: |
71
-
Cloud.gov is FedRAMP Authorized (Moderate). When you build on our platform, you can reuse our authorization package and inherit the platform-level controls that we operate and continuously maintain. This reduces the scope of your own compliance work, but you are still responsible for controls specific to your application.
72
-
items:
73
-
- heading: "Continuous monitoring and reporting (platform)"
74
-
text: "We perform monthly vulnerability scans, POA&M updates, incident reporting, and annual assessments that align with FY 2025 FISMA CIO metrics under OMB M-25-04."
75
-
- heading: "Operational safeguards managed by Cloud.gov"
76
-
text: "Platform patching, automated backups, centralized logging, and incident alerting are implemented and mapped to NIST 800-53 Rev. 5 control families such as SI, AU, and CM."
text: "Container networking is encrypted and isolated, with short-lived credentials and granular access policies—meeting the intent of EO 14028 and CISA’s Zero Trust Maturity Model at the platform layer."
79
-
outro: |
80
-
These inherited controls mean your agency has fewer items to implement and assess. You remain responsible for securing your application code, data, and any customer-specific configurations, while Cloud.gov manages the underlying infrastructure and platform controls.
71
+
Cloud.gov is already FedRAMP Authorized (Moderate), so your agency can reuse our compliance package. That means on day one, your **platform layer** already meets these mandates:
72
+
content: |
73
+
- Continuous monitoring, monthly vulnerability scans, POA&M updates, incident reporting, and annual assessments — all performed for the **platform itself**, satisfying key FY 2025 FISMA CIO metrics under OMB M-25-04.
74
+
75
+
- Platform patching, automated backups, centralized logging, and incident alerting mapped to **NIST 800-53 Rev. 5 control families like SI, AU, and CM**.
76
+
77
+
- Encrypted, isolated networking between containers with short-lived credentials and granular access policies — aligned with **EO 14028 and CISA’s Zero Trust Maturity Model**.
0 commit comments