FedRAMP Trigrams¶
FedRAMP uses trigrams (three-letter acronyms, initialisms, or abbreviations) to uniquely identify collections, rulesets, ruleset subsets, and Key Security Indicator themes.
This table allows folks to quickly find the corresponding collection, ruleset, ruleset subset, or Key Security Indicator theme for each trigram.
| Trigram | Name | Type |
|---|---|---|
| ADP | Adaptive Changes | Ruleset subset |
| AFC | Addressing FedRAMP Communication | Ruleset |
| AGC | General Agency Responsibilities | Ruleset subset |
| AGM | Agency Guidance | Ruleset subset |
| AGU | Agency Use of FedRAMP Certified Cloud Services | Ruleset |
| APP | Applying for FedRAMP Certification | Ruleset subset |
| APS | Applying for FedRAMP Certification with an Agency Sponsor | Ruleset subset |
| CAS | General Advisor Responsibilities | Ruleset subset |
| CCL | Changing Certification Class | Ruleset subset |
| CCM | Collaborative Continuous Monitoring | Ruleset |
| CDS | Certification Data Sharing | Ruleset |
| CED | Cybersecurity Education | KSI theme |
| CLA | FedRAMP Class A Certification Rules | Ruleset subset |
| CMT | Change Management | KSI theme |
| CMU | Cryptographic Module Use | Ruleset |
| CNA | Cloud Native Architecture | KSI theme |
| CPO | Certification Package Overview | Ruleset |
| CSO | General Provider Responsibilities | Ruleset subset |
| CTL | Rev5 Control Guidance | Collection |
| ENH | Enhanced Capabilities | Ruleset subset |
| EVA | Evaluation | Ruleset subset |
| FRC | FedRAMP Certification | Ruleset |
| FRD | FedRAMP Definitions | Collection |
| FRP | FedRAMP Responsibilities | Ruleset subset |
| FRR | FedRAMP Rules | Collection |
| IAM | Identity and Access Management | KSI theme |
| IAS | General Independent Assessor Responsibilities | Ruleset subset |
| IEC | Incident Evaluation and Communication | Ruleset |
| IIP | Provider Responsibilities for Initial Implementation Phase Listings | Ruleset subset |
| INR | Incident Response | KSI theme |
| IVV | Independent Verification and Validation | Ruleset |
| KSI | Key Security Indicators | Collection |
| MAS | Minimum Assessment Scope | Ruleset |
| MKT | Marketplace Listing | Ruleset |
| MLA | Monitoring, Logging, and Auditing | KSI theme |
| OCR | Ongoing Certification Reports | Ruleset subset |
| PIY | Policy and Inventory | KSI theme |
| QTR | Quarterly Reviews | Ruleset subset |
| REC | FedRAMP Recognition of Independent Assessment Services | Ruleset |
| RPL | Recovery Planning | KSI theme |
| RPT | Reporting | Ruleset subset |
| RTR | Routine Recurring Changes | Ruleset subset |
| SCG | Secure Configuration Guide | Ruleset |
| SCN | Significant Change Notification | Ruleset |
| SCR | Supply Chain Risk | KSI theme |
| SDR | Security Decision Record | Ruleset |
| SPN | Agency Sponsored Certifications | Ruleset subset |
| SVC | Service Configuration | KSI theme |
| TFR | Timeframes | Ruleset subset |
| TRC | FedRAMP-Compatible Trust Centers | Ruleset subset |
| TRF | Transformative Changes | Ruleset subset |
| USE | Use of FedRAMP Certifications | Ruleset subset |
| UTC | Using a Trust Center | Ruleset subset |
| VDR | Vulnerability Detection and Response | Ruleset |
| VER | Vulnerability Evaluation and Reporting | Ruleset |