Available on Demand | April 22-24, 2025 | 1 Hour Each | 3 CPE

GovRAMP was introduced in 2020 to give cloud service providers (CSPs) serving state and local governments a structure to verify their security posture and prove their cybersecurity compliance to government clients.

Since then, state and local agencies have accelerated cloud adoption. In just four years, GovRAMP’s baseline of cyber requirements and standards has shown agencies and companies alike the value of building a coordinated approach to security, privacy and regulatory compliance. So far more than two dozen states are participating and more than 400 vendors – many of which also meet FedRAMP standards – have been GovRAMP-certified.

GovRAMP Host & Moderator:

Michael Kennedy, Moderator & Contributing Editor, FedInsider

Michael Kennedy
Contributing Editor,
FedInsider

GovRAMP Day One: Finding Your Best Strategy for a Multi-Cloud Environment

One consideration for state CIOs is whether to maintain a multi-cloud environment. Having more than one cloud provides the opportunity for state agencies to pick and choose among the different providers for the best fit to meet their needs – but running multiple clouds can be expensive and technically challenging to manage.

Among the considerations: How well does an agency understand its use case, to help decide which cloud to use? This means everything from understanding the agency’s data storage requirements to tracking the amount of data being shipped back and forth; knowing which tools the agency already has in-house and whether other tools are needed; and having the resources to address security requirements throughout the organization.

Learning Objectives:

  • Identify the various criteria that define the differences between CSPs and how agencies can apply those criteria to their own workflows

  • List the best practices as described by practitioners and how they fit your agency’s work environment

  • Review the GovRAMP requirements for cybersecurity and how well different CSPs integrate with your agency’s current security measures

Dan Wilkins, Chief Information Security Officer, Arizona Department of Economic Security

Dan Wilkins
CISO, Arizona Department
of Economic Security
Jessica Van Eerde, Chief Operating Officer & General Counsel, GovRAMP

Jessica Van Eerde
COO & General Counsel,
GovRAMP
Nick Peters, Information Security Program Manager, Rubrik

Nick Peters
Information Security Program
Manager,
Rubrik

GovRAMP Day Two: Ensuring Data Security & Compliance

GovRAMP is all about cybersecurity – built on the National Institute of Standards and Technology’s (NIST) Special Publication 800-53 Rev. 4 framework, based on and similar to FedRAMP, it works on a “complete once, use many” model intended to save both time and money for state governments and CSPs alike.

But simply choosing a CSP from GovRAMP’s list of certified vendors does not guarantee data security and compliance with regulations. Agencies must understand what their vendors are – and are not – responsible for protecting. The agencies have to ensure that they know what they are responsible for, that they have policies, procedures, and resources in place to address their in-house security and compliance responsibilities.

Learning Objectives:

  • Review the elements of cybersecurity addressed by the NIST standard and how they are incorporated into a GovRAMP-certified cloud

  • Outline the key differences between Infrastructure as a Service (IaaS), Software as a Service (SaaS), and Platform as a Service (PaaS) in order to find the best fit for your agency

  • Understand where your agency collects and uses personally identifiable information (PII), protected health information (PHI), and payment card industry (PCI) information, and the cybersecurity measures needed to protect each one

Tony O’Neill, CISO & Chief Risk Officer, Commonwealth of Massachusetts

Tony O’Neill
CISO & Chief Risk Officer,
Commw. of Massachusetts
Fred Brittain, Executive Advisor, GovRAMP

Fred Brittain
Executive Advisor,
GovRAMP
John Israel, Assistant Commissioner & CISO, State of Minnesota

John Israel
Asst. Commissioner & CISO,
State of Minnesota
Chris Saunders, Public Sector Solutions Engineer Leader, Wiz

Chris Saunders
Public Sector Solutions
Engineer Leader,
Wiz

GovRAMP Day Three: Building a Compliance Framework for Providers & Agencies

Building a cybersecurity-compliance framework is about more than simply purchasing services from a GovRAMP-certified provider. For instance, GovRAMP itself states that “using an infrastructure with a GovRAMP Authorized status does not automatically make the service provider’s system GovRAMP compliant. Each layer (e.g. IaaS, PaaS, and SaaS) must be evaluated on its own for the provider to obtain a GovRAMP Authorized status.”

Agencies have to evaluate the NIST standards upon which GovRAMP certification is built to determine what steps they need to take internally to create a compliance framework.

Learning Objectives:

  • Understand the structure of the NIST cybersecurity framework, including which elements are agencies’ responsibility and which rest on the CSP

  • Identify the organizations, such as NIST, that create the standards and compliance framework in order to monitor for changes or additional guidance

Jeff Maxon, Chief Information Technology Officer, State of Kansas

Jeff Maxon
Chief Information Technology
Officer,
State of Kansas
Leah McGrath, Executive Director, GovRAMP

Leah McGrath
Executive Director,
GovRAMP
Michael Gregg, Field CIO, Palo Alto Networks

Michael Gregg
Field CISO,
Palo Alto Networks

FI-Carahsoft-PaloAlto-Rubrik-Wiz-CPS-Series-Color-Logos