Skip to content

/stateramp-expert

StateRAMP expert for state and local government cloud services. Deep knowledge of State Risk and Authorization Management Program including Low/Moderate impact levels, NIST 800-53 controls, state-specific requirements, FedRAMP alignment, and multi-state authorization strategies.

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill stateramp-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/stateramp-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

StateRAMP expert for state and local government cloud services. Deep knowledge of State Risk and Authorization Management Program including Low/Moderate impact levels, NIST 800-53 controls, state-specific requirements, FedRAMP alignment, and multi-state authorization strategies.

SKILL.md

stateramp-expert.SKILL.md
name: stateramp-expert
description: StateRAMP expert for state and local government cloud services. Deep knowledge of State Risk and Authorization Management Program including Low/Moderate impact levels, NIST 800-53 controls, state-specific requirements, FedRAMP alignment, and multi-state authorization strategies.
allowed-tools: Read, Glob, Grep, Write

StateRAMP Expert

Deep expertise in StateRAMP (State Risk and Authorization Management Program) for cloud service providers serving state and local government agencies.

Expertise Areas

StateRAMP Program Overview

**Purpose**: Standardized, reusable security authorization framework for state and local government cloud services **Authority**: State-level (not federal) **Based On**: FedRAMP framework, adapted for state/local needs **Launch**: 2015 (evolved from state reciprocity initiatives) **Current Status**: 15+ participating states, growing adoption

**Program Goals**:

  • Reduce duplicative state-by-state assessments
  • Lower costs for CSPs and states
  • Standardize security baselines
  • Enable reciprocity across states
  • Accelerate secure cloud adoption

StateRAMP vs FedRAMP Comparison

| Aspect | StateRAMP | FedRAMP | |--------|-----------|---------| | **Authority** | State/local government | Federal government | | **Governance** | StateRAMP Impact Council | GSA, DHS, DOD (JAB) | | **Market** | 50 states, territories, localities | Federal agencies | | **Cost** | 20-30% lower typically | $200K-$1M+ | | **Timeline** | 6-18 months | 12-24+ months | | **Reciprocity** | Across participating states | Across federal agencies | | **Controls** | NIST 800-53 (state-tailored) | NIST 800-53 Rev 5 | | **Impact Levels** | Low, Moderate | Low, Moderate, High | | **Assessment** | StateRAMP-recognized 3PAO | FedRAMP-authorized 3PAO |

**Similarities**:

  • NIST 800-53 control framework
  • Third-party assessment required
  • Continuous monitoring mandatory
  • Similar documentation (SSP, SAP, SAR, POA&M)
  • Annual assessments
  • Significant change notifications

**Key Differences**:

  • **Scope**: States vs. federal agencies
  • **Data Types**: State data vs. federal CUI/FCI
  • **Cost**: StateRAMP generally less expensive (smaller scope, faster timelines)
  • **Flexibility**: States may add requirements, less rigid than FedRAMP
  • **Market Size**: 50 states + locals vs. federal enterprise
  • **Leverage**: FedRAMP authorization helps StateRAMP but not reciprocal

StateRAMP Impact Levels

StateRAMP uses FIPS 199 categorization:

**Low Impact (~125 controls)**:

  • **Data**: Public information, non-sensitive
  • **Systems**: Public-facing services, informational systems
  • **Impact**: Limited adverse effect if compromised
  • **Examples**:
  • Event calendars
  • Public document repositories
  • General constituent communication
  • Non-sensitive form submissions
  • **Cost**: $50K-$150K assessment + remediation
  • **Timeline**: 6-12 months

**Moderate Impact (~325 controls)**:

  • **Data**: CUI, PII, PHI, financial, law enforcement sensitive
  • **Systems**: Mission-critical, sensitive data processing
  • **Impact**: Serious adverse effect if compromised
  • **Examples**:
  • Tax systems
  • Benefits administration (SNAP, Medicaid)
  • HR/Payroll systems
  • Law enforcement case management
  • Licensing with PII
  • Healthcare portals
  • Financial management
  • **Cost**: $150K-$400K assessment + remediation
  • **Timeline**: 12-18 months

**High Impact**:

  • Not currently defined in StateRAMP
  • States with high-impact needs typically use FedRAMP High or custom authorizations
  • May emerge in future StateRAMP versions

NIST 800-53 Control Families

StateRAMP uses NIST SP 800-53 control framework:

**18 Control Families**:

1. **Access Control (AC)** - 25 controls at Moderate

  • Account management (AC-2)
  • Least privilege (AC-6)
  • Remote access (AC-17)
  • Wireless access (AC-18)
  • Access control for mobile devices (AC-19)

2. **Awareness and Training (AT)** - 5 controls

  • Security awareness (AT-2)
  • Role-based training (AT-3)
  • Security training records (AT-4)

3. **Audit and Accountability (AU)** - 12 controls

  • Audit events (AU-2)
  • Content of audit records (AU-3)
  • Audit storage capacity (AU-4)
  • Response to audit failures (AU-5)
  • Audit review, analysis, reporting (AU-6)
  • Audit reduction and report generation (AU-7)
  • Time stamps (AU-8)
  • Protection of audit information (AU-9)
  • Audit record retention (AU-11)

4. **Security Assessment and Authorization (CA)** - 9 controls

  • Security assessments (CA-2)
  • System interconnections (CA-3)
  • Plan of action and milestones (CA-5)
  • Security authorization (CA-6)
  • Continuous monitoring (CA-7)
  • Penetration testing (CA-8)

5. **Configuration Management (CM)** - 11 controls

  • Baseline configuration (CM-2)
  • Configuration change control (CM-3)
  • Security impact analysis (CM-4)
  • Access restrictions for change (CM-5)
  • Configuration settings (CM-6)
  • Least functionality (CM-7)
  • Information system component inventory (CM-8)

6. **Contingency Planning (CP)** - 10 controls

  • Contingency plan (CP-2)
  • Contingency training (CP-3)
  • Contingency plan testing (CP-4)
  • Information system backup (CP-9)
  • Information system recovery and reconstitution (CP-10)

7. **Identification and Authentication (IA)** - 11 controls

  • Identification and authentication (organizational users) (IA-2)
  • Device identification and authentication (IA-3)
  • Identifier management (IA-4)
  • Authenticator management (IA-5)
  • Authenticator feedback (IA-6)
  • Cryptographic module authentication (IA-7)

8. **Incident Response (IR)** - 10 controls

  • Incident response training (IR-2)
  • Incident response testing (IR-3)
  • Incident handling (IR-4)
  • Incident monitoring (IR-5)
  • Incident reporting (IR-6)
  • Incident response assistance (IR-7)
  • Incident response plan (IR-8)

9. **Maintenance (MA)** - 6 controls

  • System mainte
Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked