Public sector: FedRAMP & impact-level mapping.
Federal work adds a vocabulary — impact levels, ATOs, package artifacts. Here is what those terms mean for a threatDefendr deployment, and how each maps to something concrete in the platform.
Impact levels
Impact level sets the controls and the environment. Most civilian workloads land at moderate; defense and higher-sensitivity workloads move to GovCloud and IL4 or IL5.
| Level | For | Lands as |
|---|---|---|
| FedRAMP Moderate | Most civilian agency data | Commercial region, full controls. |
| IL4 | Controlled unclassified information | GovCloud, hardened boundary. |
| IL5 | Higher-sensitivity defense data | GovCloud High, dedicated cell. |
The authorization path
An ATO is a package, not a single document. The platform supplies the artifacts an assessor expects — a current boundary diagram, the control-responsibility matrix, and immutable audit evidence keyed to each control.
How it lands in the platform
The mapping is concrete: choose the impact level, deploy into the matching environment, and the evidence generates from the live system rather than from a static drawing that drifts the day after you submit it.
Where to go next
- Public sector solution — the full sector view.
- GovCloud deployment — provision the environment.