With moderator permission: r/FederalCyber for broader federal cybersecurity practice
Hi everyone. With the moderator team's permission, I wanted to introduce r/FederalCyber, an independent and unofficial community for public-source discussion spanning FedRAMP implementation, RMF and NIST controls, government cloud, ATO evidence, continuous monitoring, zero trust, incident response, and workforce questions.
r/FedRAMP remains the place for FedRAMP-specific discussion. The new community is intended for cross-cutting questions that sit between authorization, engineering, operations, and mission risk. The opening threads focus on evidence that controls actually work, inherited-responsibility gaps, vulnerability prioritization under VDR and VER, and how to share lessons without exposing protected operational details.
The boundaries are strict: no CUI, credentials, customer or agency identifiers, internal architecture, active incident data, nonpublic vulnerabilities, or implied government endorsement. Vendor link drops and low-effort promotion are not welcome.
If that broader scope fits your work, I would value your experience and criticism: https://www.reddit.com/r/FederalCyber/