Zscaler Internet Access (ZIA) has achieved Federal Risk and Authorization Management Program (FedRAMP) High Authority to Operate, indicating the Zscaler solution meets government agencies’ highest security requirements. 

ZIA is currently the only secure access service edge (SASE) trusted internet connections 3.0 solution that has achieved FedRAMP’s highest authorization, according to a Zscaler announcement.

Zscaler Chief Compliance Officer Stephen Kovac told SDxCentral that the highest authorization level is “considered to be the crème de la crème of FedRAMP.” 

Zscaler Private Access (ZPA) is also FedRAMP Joint Authorization Board (JAB) High Authorized. Together, ZIA and ZPA comprise the FedRAMP high-authorized Zscaler Zero Trust Exchange for federal customers. 

[caption id="attachment_120537" align="aligncenter" width="250"] Stephen Kovac, chief compliance officer, Zscaler[/caption]

What is FedRAMP?

FedRAMP is a government-wide program with input from several government groups and departments. The program’s primary decision-making body, JAB, is composed of CIOs from the Department of Defense (DOD), Department of Homeland Security, and General Services Administration. FedRAMP ensures government-wide information systems and services have sufficient security and reduces risk management costs.

The Zscaler authorization follows VMware’s July announcement that its Government Services offering also achieved FedRAMP High Authorization from the JAB.

'Tough' JAB High Authorization Process

The FedRAMP program has two types of authorization: JAB authorization and agency authorization, with the former being more difficult to achieve. 

According to Kovac, the Federal Communications Commission initially sponsored Zscaler to go into the FedRAMP program for agency authorization. The ZIA and ZPA platforms were first authorized at the moderate agency level, but as Zscaler matured — with its customer base expanding from civilian agencies to cabinet agencies like the DOD — the company had to “relaunch [its] platform at a different level.”

“Saying that you're a FedRAMP High Authorized cloud service provider and you went through the JAB, that is probably the highest level you can get to,” Kovac said. 

Zscaler spent two years achieving JAB authorization. Kovac noted that High Authorization requires over 400 controls. 

“The certification process is long. It's tough,” he said. “Every control is questioned and re-questioned. So you really have to perform and you have to make sure that there are no holes in your system, because they're going to look at every single control.”

Another consideration during the process was whether or not Zscaler's partner solutions met the JAB’s high-level requirements, Kovac added. 

“That's very tough, because there's some really great products out there that we use in our moderate platform today that just aren't available. There's nobody that delivers them at a high baseline,” he said. “We have to then redesign our system and partner up with all the other folks that are at high [level].” 

Kovac indicated that even with ZIA having achieved the highest level of authorization, the company's work isn’t done. 

“When you have these authorizations you have to, every year, continue them,” Kovac said. Continuous monitoring will still be necessary, he added, meaning Zscaler will have to ensure its systems are kept running in compliance with the JAB’s standards. 

With three different FedRAMP processes under his belt, Kovac said he tells service providers interested in the JAB authorization to prepare for the maintenance. “Getting your certification is one thing, but you better plan the same amount of time each year to maintain it," he added.