FedRAMP at Gobo

FedRAMP at Gobo

Gobo is certified at FedRAMP Moderate (Class C), ensuring your agency’s data is secured with comprehensive, state-of-the-art controls.

Explore our official listing on the FedRAMP Marketplace. To receive access to our FedRAMP Package, use the Package Access Request Form.

For more details, contact us at info@goboframework.com.

FedRAMP Secure Configuration Guide

This document provides the secure configuration requirements for the Gobo platform in accordance with FedRAMP (NIST SP 800-53 Rev. 5) standards.

Gobo is designed with a "Secure by Default" posture. Most security configurations, including infrastructure hardening and encryption, are managed by Gobo. The Agency’s primary security configuration responsibility lies in Role-Based Access Control (RBAC).

Role-Based Access Control

Access is granted at the organization level and further refined by I2App roles.

Default Posture

When a new user is added to a Gobo organization, they are assigned no default roles. They will have no visibility or functional access until a role is explicitly granted.

Role Tiers

Access to specific applications (I2Apps) is categorized into three intuitive tiers. Agencies should assign these based on the least privilege principle:

  1. Viewer: Read-only access suitable for stakeholders who only need to view results.

  2. Operator: Functional access allowing users to perform standard actions within an I2App but prevents administrative changes.

  3. Admin: Administrative control over the specific I2App, including configuration settings.

Organization Admin

During onboarding, the agency identifies specific "Organization Admins." These users have the authority to manage other users and assign roles directly within the Gobo Admin interface.

Administrative Request Procedures

For agencies that prefer Gobo Customer Service manage their user lifecycle, the following security protocol is enforced:

  • Authorized Requestors: Gobo maintains an allow list of designated agency personnel authorized to request administrative changes.

  • Verification: Requests are cross-referenced against this authorized list. Requests from unauthorized addresses or individuals will be denied.

  • Separation of Duties: Agency personnel should periodically review the list of authorized requestors to ensure it remains current, especially during staff offboarding.

Account Management and Offboarding

The Agency is responsible for the timely notification of user departures.

  1. IdP Deactivation: When a user leaves the agency, their account should be disabled in the Agency's SAML IdP immediately. This prevents any further access to Gobo.

  2. Gobo Notification: The Agency should notify Gobo Support or use an Organization Admin account to disable the user from the organization to maintain a clean user inventory.

Note that past revisions of the Secure Configuration Guide will be linked from this page when they become available.