Government Command Center 16 items
Municipal Cybersecurity & StateRAMP Cloud Vendor Checklist
Evaluates a local government's cybersecurity posture and the StateRAMP authorization status of cloud service providers handling government data.
StateRAMPNIST SP 800-53NIST CSFNIST SP 800-171
Free PDF · enter your email to download.
Governance & Framework
- Has the jurisdiction adopted a recognized cybersecurity framework (e.g., NIST Cybersecurity Framework)? *
- Is a written information security policy approved and periodically reviewed? *
- Is a CISO or designated security official assigned responsibility for the program? *
StateRAMP Cloud Vendor Authorization
- Do cloud service providers handling government data hold a StateRAMP Authorized or Ready status at the appropriate impact level? *
- Was the required StateRAMP impact level (Low, Moderate, High) determined from the data categorization? *
- Is the StateRAMP requirement written into the procurement and contract? *
- Is the vendor's continuous monitoring status reviewed via the StateRAMP Authorized Product List? *
Access Control & Identity
- Is multi-factor authentication enforced for remote and privileged access? *
- Is least-privilege access reviewed and enforced for government systems? *
- Are user accounts promptly disabled upon separation or role change? *
Protective Controls
- Are systems patched on a defined vulnerability-management cycle? *
- Are backups performed, tested, and stored offline/immutably to support ransomware recovery? *
- Is security awareness training provided to all personnel at least annually? *
Detection & Incident Response
- Is a documented incident response plan maintained and periodically exercised? *
- Are cyber incidents reported to the required authorities (e.g., state fusion center, CISA, MS-ISAC)? *
- Is logging and monitoring in place to detect unauthorized activity? *
Download the full Municipal Cybersecurity & StateRAMP Cloud Vendor Checklist checklist
Get it as a clean, printable PDF — free.
