Available on Demand | April 22-24, 2025 | 1 Hour Each | 3 CPE
GovRAMP was introduced in 2020 to give cloud service providers (CSPs) serving state and local governments a structure to verify their security posture and prove their cybersecurity compliance to government clients.
Since then, state and local agencies have accelerated cloud adoption. In just four years, GovRAMP’s baseline of cyber requirements and standards has shown agencies and companies alike the value of building a coordinated approach to security, privacy and regulatory compliance. So far more than two dozen states are participating and more than 400 vendors – many of which also meet FedRAMP standards – have been GovRAMP-certified.
In three sessions, over three consecutive days, thought leaders from government and industry will share their experiences working with GovRAMP, the challenges they are looking to solve, and what they consider best practices for utilizing GovRAMP’s capabilities most effectively.
Accreditation:
Participants can earn 3 CPE credit in Business Management & Organization.*
* To receive CPE credit you must arrive on time and participate in the surveys throughout the webinar. Certificates will be e-mailed to registrants. In accordance with the standards of the National Registry of CPE Sponsors, 50 minutes equals 1 CPE. By providing your contact information to us, you agree: (i) to receive promotional and/or news alerts via email from Federal News Network and our third party partners, (ii) that we may share your information with our third party partners who provide products and services that may be of interest to you and (iii) that you are not located within the European Economic Area.
What is CART?
CART (communication access realtime translation) provides instant accessibility for all participants by delivering the spoken word as a realtime stream of text.
CART Captioner Professional Certifications
Our CART services are provided by Home Team Captions. All of our CART captioners hold, at minimum, the CCP (Certified CART Provider) certification, or higher, from NCRA (National Court Reporters Association.)
To view the CART feed for this webinar: Register for this webinar, login from the link provided, and click on the CART Tab and click the link to begin using CART.
GovRAMP Host & Moderator:
GovRAMP Day One: Finding Your Best Strategy for a Multi-Cloud Environment
One consideration for state CIOs is whether to maintain a multi-cloud environment. Having more than one cloud provides the opportunity for state agencies to pick and choose among the different providers for the best fit to meet their needs – but running multiple clouds can be expensive and technically challenging to manage.
Among the considerations: How well does an agency understand its use case, to help decide which cloud to use? This means everything from understanding the agency’s data storage requirements to tracking the amount of data being shipped back and forth; knowing which tools the agency already has in-house and whether other tools are needed; and having the resources to address security requirements throughout the organization.
Learning Objectives:
GovRAMP Day Two: Ensuring Data Security & Compliance
GovRAMP is all about cybersecurity – built on the National Institute of Standards and Technology’s (NIST) Special Publication 800-53 Rev. 4 framework, based on and similar to FedRAMP, it works on a “complete once, use many” model intended to save both time and money for state governments and CSPs alike.
But simply choosing a CSP from GovRAMP’s list of certified vendors does not guarantee data security and compliance with regulations. Agencies must understand what their vendors are – and are not – responsible for protecting. The agencies have to ensure that they know what they are responsible for, that they have policies, procedures, and resources in place to address their in-house security and compliance responsibilities.
Learning Objectives:
GovRAMP Day Three: Building a Compliance Framework for Providers & Agencies
Building a cybersecurity-compliance framework is about more than simply purchasing services from a GovRAMP-certified provider. For instance, GovRAMP itself states that “using an infrastructure with a GovRAMP Authorized status does not automatically make the service provider’s system GovRAMP compliant. Each layer (e.g. IaaS, PaaS, and SaaS) must be evaluated on its own for the provider to obtain a GovRAMP Authorized status.”
Agencies have to evaluate the NIST standards upon which GovRAMP certification is built to determine what steps they need to take internally to create a compliance framework.
Learning Objectives:












