{"id":347,"date":"2021-05-25T18:03:55","date_gmt":"2021-05-25T18:03:55","guid":{"rendered":"https:\/\/terrabioappdev.wpenginepowered.com\/terra-security-affirmed-by-fedramp\/"},"modified":"2023-12-27T04:54:44","modified_gmt":"2023-12-27T04:54:44","slug":"terra-security-affirmed-by-fedramp","status":"publish","type":"post","link":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/","title":{"rendered":"Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP)"},"content":{"rendered":"<p><i><span style=\"font-weight: 400;\">As announced in a <\/span><\/i><a href=\"https:\/\/www.broadinstitute.org\/node\/894666\"><i><span style=\"font-weight: 400;\">recent press release<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">, the Broad Institute has been awarded the high profile &#8220;FedRAMP Moderate&#8221; security authorization for the operation of the Terra platform. In this guest blog post, David Bernick, Chief Information Security Officer at the Broad Institute, gives us insight into the FedRAMP program and explains what this means for researchers using Terra to access, analyze and share sensitive data.\u00a0<\/span><\/i><\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">A core piece of our mission is to serve science by enabling secure data sharing at scale, and make possible the federated data analyses that will catalyze the next generation of breakthroughs in biomedical science. Yet for all the sophisticated machinery involved, the success of this entire enterprise relies on something fundamentally human: acts of trust, by individuals and institutions who choose to entrust us with their most personal data, such as genomes and phenotypes.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Part of how we earn that trust is by communicating clearly how we keep data secure, and by having credible third parties affirm our procedures. To that end, the Federal Risk and Authorization Management Program (FedRAMP) is an incredibly valuable framework. FedRAMP Authorization means that multiple auditors (who themselves are audited by the US Federal Government) have looked at every security control we have, as well as the quality of security <\/span><i><span style=\"font-weight: 400;\">around<\/span><\/i><span style=\"font-weight: 400;\"> each of those controls, and affirmed them.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Importantly, FedRAMP is not a \u201cmoment in time\u201d authorization, but rather, evidence that security is an ongoing, growing, real effort. This is critical because the threat landscape is complex and always changing, with bad actors ranging from nation states and state-sponsored attackers pursuing geopolitical agendas, to hackers and criminal enterprises seeking profit such as opportunistic crypto-currency miners looking for spare CPU cycles anywhere. In such a context, information security is about much more than merely stomping out each threat as it appears, like some game of &#8220;whack-a-mole&#8221;. Abiding by FedRAMP involves having a security program that is flexible and dynamic enough to keep up with these challenges.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">A federal standard for excellence in information security<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">The Federal Risk and Authorization Management Program (FedRAMP) is a US government program that is designed to standardize how federal agencies evaluate the security of cloud-based products and services, while recognizing that certain agencies may have distinct security requirements due to the nature of the functions they perform and of the data they handle and their own levels of risk tolerance.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The program is based on a information security framework called <\/span><a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-53\/rev-5\/final\"><span style=\"font-weight: 400;\">NIST-800-53<\/span><\/a><span style=\"font-weight: 400;\">, developed by the National Institute of Standards and Technologies (NIST), that spells out a set of security and privacy controls designed to protect data on computer systems. Incidentally, those of you in the genomics space might recognize the NIST acronym \u2014 yes, it&#8217;s the same NIST that is behind the <\/span><a href=\"https:\/\/www.nist.gov\/programs-projects\/genome-bottle\"><span style=\"font-weight: 400;\">Genome In A Bottle<\/span><\/a><span style=\"font-weight: 400;\"> benchmarking framework.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Any organization applying for FedRAMP authorization for a cloud-based product or service has to demonstrate that their security program implements all relevant security controls prescribed in the NIST-800-53 framework. This is done through a series of audits conducted by an authorized third party assessor, called a Third Party Assessment Organization (3PAO), who systematically reviews and tests every security control, and reports their findings to the FedRAMP Program Management Office (PMO). If the third party assessor finds any gaps or issues with the security controls, the applicant has to remediate them, or provide a plan for doing so, within a specific timeframe. The FedRAMP PMO then reviews the findings and audits THOSE findings and remediations. All of this typically involves a lot of back and forth, which can take quite some time; the discussions are both deeply technical and deeply process-driven.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-large wp-image-943\" src=\"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/FEDRAMP-workflow-1024x267.png\" alt=\"\" width=\"800\" height=\"209\" \/><\/p>\n<p><i><span style=\"font-weight: 400;\">Process diagram for Agency Authorization, Section 4.2 the <\/span><\/i><a href=\"https:\/\/www.fedramp.gov\/assets\/resources\/documents\/CSP_Authorization_Playbook_Getting_Started_with_FedRAMP.pdf\"><i><span style=\"font-weight: 400;\">FedRAMP CSP Authorization Playbook<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">. The System Security Plan (SSP) and Security Assessment Plan (SAP) are developed by the Third Party Assessment Organization (3PAO).\u00a0<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">The end result is the coveted &#8220;Authority To Operate&#8221; or ATO, which is granted to the applicant for the specific service that was subjected to this process. The ATO is delivered with a qualifier that can be &#8220;Low&#8221;, &#8220;Moderate&#8221; or &#8220;High&#8221;, which is based on the type of data that will be handled by the service, and, crucially, how severe the consequences would be if a security breach were to occur. The highest rating is reserved for use cases where a breach could lead to serious material or strategic damages and potential loss of life.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">While the ATO process is sponsored by a specific federal agency within the US government who declares that they want to use the service, achieving ATO means that any federal agency can then use that service. Other agencies still have to do their due-diligence, but the process is much faster when a product has ATO. The evaluation and risk assessment steps typically happen much faster, because all the previous documentation, audits, and reports are available for other agencies to use, and they can quickly determine whether the FedRAMP office has affirmed that the service under review operates at or above the level of security they require.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You can see all this reflected in the <\/span><a href=\"https:\/\/marketplace.fedramp.gov\/#!\/products?sort=productName\"><span style=\"font-weight: 400;\">FedRAMP Marketplace<\/span><\/a><span style=\"font-weight: 400;\">, which lists the number of active authorizations granted to each product or service, with the relevant impact level rating.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-large wp-image-949\" src=\"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-mktplace-1-1024x404.png\" alt=\"\" width=\"800\" height=\"316\" \/><\/p>\n<p><i><span style=\"font-weight: 400;\">Composite screenshot from the FedRAMP Marketplace website showing the entries for Terra, Microsoft Azure and Google Cloud Platform. Any platform that Terra relies on for its operation must have its own FedRAMP ATO.\u00a0<\/span><\/i><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">In our case, Broad Institute is the service provider; the federal agency who sponsored the ATO is the National Heart, Lung and Blood Institute (NHLBI) under the National Institutes of Health (NIH) which is itself under the Department of Health and Human Services (HHS); and Terra is the service for which we received the ATO, rated at the &#8220;Moderate&#8221; level. Following the logic described above, if another agency, say the Food and Drug Administration or the Veterans Administration, wants to use Terra we&#8217;ll be able to leverage all the work we did to get the ATO for NHLBI, and those organizations can re-use all of those assessments and documents. While a FedRAMP ATO isn\u2019t a \u201crubber-stamp\u201d of approval, it sets a high level of trust for government entities and makes approval processes faster.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Our journey to receiving the FedRAMP Moderate ATO for Terra<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">This was not our first experience with federal security compliance. We received our first federal ATO under the Federal Information Security Modernization Act (FISMA) for FireCloud, Terra&#8217;s precursor, which we originally developed under the Cloud Pilots program of the National Cancer Institute (NCI) to host cancer genomics datasets such as TCGA and TARGET. Like FedRAMP, the FISMA program is based on the NIST-800-53 framework, but it is an earlier implementation that is more dataset-centric. When the original FireCloud platform evolved into Terra, the FISMA ATO still applied for the use of the NCI datasets.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Meanwhile, more NIH institutes and centers were beginning to show interest in using Terra, which gave rise to the vision of combining datasets from multiple federal programs in novel ways to allow for joint analysis in a secure multi-tenant enclave. We could \u2014 and did \u2014 pursue FISMA ATO for additional federal projects, but we determined that, as we continued to mature our information security program, it would be more logical to pursue FedRAMP ATO.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">And so we did; and here we are. This moment is the culmination of 18 months of hard work (in the middle of a pandemic!) by our Information Security and DevOps teams, driven by Sarah Tahiri, Senior Information Security Program Manager in the Broad&#8217;s Data Sciences Platform. Sarah\u2019s team wrangled all the teams together to work with each other to ensure all security controls passed review, as well as making sure we had meaningful procedures and policies in place across the board.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It&#8217;s difficult to convey adequately how much work this represents. Compared to FISMA, FedRAMP requires additional security controls related to authentication, system development, and operation, as well as increased audits and frequent third-party penetration tests. And of course, the multi-day audit of EVERY security control and sub-control by the third-party auditors with their strict timelines for addressing findings, which is perhaps the most intense part of the process.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In case this sounds like a whole lot of paperwork, well, it is, but it&#8217;s also something more: a detailed examination of every part of the system, with live tests to demonstrate that they are real, effective, and function as described. It&#8217;s not just an exercise in checking the boxes; you have to prove that you&#8217;re able to operate securely and that you have a sustainable program to maintain and evolve that security over time in the face of unknown future threats.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We are immensely proud of our Information Security and DevOps teams for rising to the challenge, and credit Sarah Tahiri&#8217;s leadership and dedication for bringing this momentous effort to fruition.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Beyond FedRAMP<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Due to the stringency of the FedRAMP risk assessment process, a FedRAMP ATO is widely recognized as a mark of high quality and demonstrable security. Currently, the only other platform in our industry to boast a FedRAMP ATO is DNAnexus; we&#8217;re thrilled to join this very exclusive club!<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Yet, as the recent <\/span><a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/statements-releases\/2021\/05\/12\/fact-sheet-president-signs-executive-order-charting-new-course-to-improve-the-nations-cybersecurity-and-protect-federal-government-networks\/\"><span style=\"font-weight: 400;\">executive order<\/span><\/a><span style=\"font-weight: 400;\"> from the Biden administration states regarding the necessity to improve the information security of federal government networks, there\u2019s more work to be done. FedRAMP is an incredibly thorough and meaningful program, but in our practice, we aim to go beyond its baseline requirements, which do not fully account for some recent technology developments.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For example, the NIST-800-53 specification does not fully address modern Application Security. Accordingly and of our own initiative, we have implemented certain security controls in Terra that we consider to be critical for application security, such as in-house penetration tests that take into account the context and code of the application, threat modeling as part of our software development process for ALL new features, advanced threat detection methods, and detailed inspections of our software supply chain to ferret out vulnerabilities in third party software that we depend upon.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As daunting as all this additional work may seem, this is something we&#8217;re very comfortable with as an organization. It is part of our culture to view baseline requirements as just that, a minimum; to be exceeded, not settled on.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You can read more about our overall security approach <\/span><a href=\"https:\/\/terra.bio\/resources\/security\/\"><span style=\"font-weight: 400;\">here<\/span><\/a><span style=\"font-weight: 400;\">. If you&#8217;d like to contact our compliance team, please email infosec@broadinstitute.org.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Broad Institute has been awarded the high profile &#8220;FedRAMP Moderate&#8221; security authorization for the operation of the Terra platform. David Bernick gives us insight into the FedRAMP program and explains what this means for researchers using Terra to access, analyze and share sensitive data.\u00a0<\/p>\n","protected":false},"author":24,"featured_media":350,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[24,43,13,119,118],"tags":[120,121,122],"class_list":["post-347","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-management","category-features","category-guest-author","category-most-recent","category-security","tag-fedramp","tag-infosec","tag-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP) - Terra<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP) - Terra\" \/>\n<meta property=\"og:description\" content=\"The Broad Institute has been awarded the high profile &quot;FedRAMP Moderate&quot; security authorization for the operation of the Terra platform. David Bernick gives us insight into the FedRAMP program and explains what this means for researchers using Terra to access, analyze and share sensitive data.\u00a0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/\" \/>\n<meta property=\"og:site_name\" content=\"Terra\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-25T18:03:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-12-27T04:54:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-trust_OG.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"David Bernick\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"David Bernick\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/\"},\"author\":{\"name\":\"David Bernick\",\"@id\":\"https:\/\/terra.bio\/#\/schema\/person\/4734095d1632a6da0a262b5ef003d273\"},\"headline\":\"Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP)\",\"datePublished\":\"2021-05-25T18:03:55+00:00\",\"dateModified\":\"2023-12-27T04:54:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/\"},\"wordCount\":1763,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/terra.bio\/#organization\"},\"image\":{\"@id\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-trust_OG.png\",\"keywords\":[\"fedramp\",\"infosec\",\"security\"],\"articleSection\":[\"Data Management\",\"Features\",\"Guest Author\",\"Most Recent\",\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/\",\"url\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/\",\"name\":\"Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP) - Terra\",\"isPartOf\":{\"@id\":\"https:\/\/terra.bio\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-trust_OG.png\",\"datePublished\":\"2021-05-25T18:03:55+00:00\",\"dateModified\":\"2023-12-27T04:54:44+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#primaryimage\",\"url\":\"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-trust_OG.png\",\"contentUrl\":\"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-trust_OG.png\",\"width\":1200,\"height\":627,\"caption\":\"fedramp trust_OG\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/terra.bio\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/terra.bio\/#website\",\"url\":\"https:\/\/terra.bio\/\",\"name\":\"Terra\",\"description\":\"Science at Scale\",\"publisher\":{\"@id\":\"https:\/\/terra.bio\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/terra.bio\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/terra.bio\/#organization\",\"name\":\"Terra\",\"url\":\"https:\/\/terra.bio\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/terra.bio\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/Terra-Bio-App@2x.webp\",\"contentUrl\":\"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/Terra-Bio-App@2x.webp\",\"width\":287,\"height\":318,\"caption\":\"Terra\"},\"image\":{\"@id\":\"https:\/\/terra.bio\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/terra.bio\/#\/schema\/person\/4734095d1632a6da0a262b5ef003d273\",\"name\":\"David Bernick\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/terra.bio\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0d4359703c154835889246c7451302a87d95dcbeaf8732c0cb5ed9d5a6268e07?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0d4359703c154835889246c7451302a87d95dcbeaf8732c0cb5ed9d5a6268e07?s=96&d=mm&r=g\",\"caption\":\"David Bernick\"},\"url\":\"https:\/\/terra.bio\/author\/dbernick\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP) - Terra","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/","og_locale":"en_US","og_type":"article","og_title":"Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP) - Terra","og_description":"The Broad Institute has been awarded the high profile \"FedRAMP Moderate\" security authorization for the operation of the Terra platform. David Bernick gives us insight into the FedRAMP program and explains what this means for researchers using Terra to access, analyze and share sensitive data.\u00a0","og_url":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/","og_site_name":"Terra","article_published_time":"2021-05-25T18:03:55+00:00","article_modified_time":"2023-12-27T04:54:44+00:00","og_image":[{"width":1200,"height":627,"url":"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-trust_OG.png","type":"image\/png"}],"author":"David Bernick","twitter_card":"summary_large_image","twitter_misc":{"Written by":"David Bernick","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#article","isPartOf":{"@id":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/"},"author":{"name":"David Bernick","@id":"https:\/\/terra.bio\/#\/schema\/person\/4734095d1632a6da0a262b5ef003d273"},"headline":"Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP)","datePublished":"2021-05-25T18:03:55+00:00","dateModified":"2023-12-27T04:54:44+00:00","mainEntityOfPage":{"@id":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/"},"wordCount":1763,"commentCount":0,"publisher":{"@id":"https:\/\/terra.bio\/#organization"},"image":{"@id":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#primaryimage"},"thumbnailUrl":"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-trust_OG.png","keywords":["fedramp","infosec","security"],"articleSection":["Data Management","Features","Guest Author","Most Recent","Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/","url":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/","name":"Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP) - Terra","isPartOf":{"@id":"https:\/\/terra.bio\/#website"},"primaryImageOfPage":{"@id":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#primaryimage"},"image":{"@id":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#primaryimage"},"thumbnailUrl":"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-trust_OG.png","datePublished":"2021-05-25T18:03:55+00:00","dateModified":"2023-12-27T04:54:44+00:00","breadcrumb":{"@id":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#primaryimage","url":"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-trust_OG.png","contentUrl":"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/fedramp-trust_OG.png","width":1200,"height":627,"caption":"fedramp trust_OG"},{"@type":"BreadcrumbList","@id":"https:\/\/terra.bio\/terra-security-affirmed-by-fedramp\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/terra.bio\/"},{"@type":"ListItem","position":2,"name":"Terra security affirmed by Federal Risk and Authorization Management Program (FedRAMP)"}]},{"@type":"WebSite","@id":"https:\/\/terra.bio\/#website","url":"https:\/\/terra.bio\/","name":"Terra","description":"Science at Scale","publisher":{"@id":"https:\/\/terra.bio\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/terra.bio\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/terra.bio\/#organization","name":"Terra","url":"https:\/\/terra.bio\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/terra.bio\/#\/schema\/logo\/image\/","url":"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/Terra-Bio-App@2x.webp","contentUrl":"https:\/\/terra.bio\/wp-content\/uploads\/2023\/12\/Terra-Bio-App@2x.webp","width":287,"height":318,"caption":"Terra"},"image":{"@id":"https:\/\/terra.bio\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/terra.bio\/#\/schema\/person\/4734095d1632a6da0a262b5ef003d273","name":"David Bernick","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/terra.bio\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/0d4359703c154835889246c7451302a87d95dcbeaf8732c0cb5ed9d5a6268e07?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0d4359703c154835889246c7451302a87d95dcbeaf8732c0cb5ed9d5a6268e07?s=96&d=mm&r=g","caption":"David Bernick"},"url":"https:\/\/terra.bio\/author\/dbernick\/"}]}},"_links":{"self":[{"href":"https:\/\/terra.bio\/wp-json\/wp\/v2\/posts\/347","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/terra.bio\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/terra.bio\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/terra.bio\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/terra.bio\/wp-json\/wp\/v2\/comments?post=347"}],"version-history":[{"count":0,"href":"https:\/\/terra.bio\/wp-json\/wp\/v2\/posts\/347\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/terra.bio\/wp-json\/wp\/v2\/media\/350"}],"wp:attachment":[{"href":"https:\/\/terra.bio\/wp-json\/wp\/v2\/media?parent=347"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/terra.bio\/wp-json\/wp\/v2\/categories?post=347"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/terra.bio\/wp-json\/wp\/v2\/tags?post=347"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}