Skip to content

United States Department of the Treasury: Treasury Cloud Moderate

FedRAMP AuthorizedRev5Moderate · since May 6, 2014

What its stage means

An agency or the FedRAMP program authorized it. Agencies can reuse that authorization.

See it on the FedRAMP Marketplace

Share this page:LinkedInXEmail

The provider's description

The Treasury Cloud Moderate (TCloud-M) System is owned and operated by the Department of the Treasury, serving as a multi-tenant IaaS/PaaS hosting environment designed to process Moderate Impact level information. TCloud-M is offered as a shared service, available in two cloud hosting models: Boundary Protected and Managed. The IaaS/PaaS provider used for this solution is Amazon Web Services (AWS) US East/West. The TCloud-M platform enables Treasury customers to concentrate on the operational and business aspects of their web presence, such as usability, information architecture, and content authoring, without the need to repeatedly configure and reinvent the technical infrastructure. This platform supports a variety of highly available services hosted on AWS and delivered to end-users through the Akamai Content Delivery Network (CDN). TCloud-M provides the following boundary protected and managed services to meet business or mission requirements: Boundary Protected Hosting Environment • Cloud account provisioning and invoicing, with transparency on service utilization with FinOps dashboards. • Intrusion Prevention Services (IPS); VPN; Direct connection with Treasury T-NET network. • Monitoring of network ingress and egress traffic. • Preconfigured networking resources. • Single Sign-On with connection to TCloud Active Directory. • IAM policies, groups, roles, preconfigured to enforce identify guardrails. • Audit trails and change monitoring that produce alerts and notifications to predetermined set of stakeholders. • Management, configuration, and provisioning of Atlassian software suite available for customers- JIRA, Confluence, Stash (BitBucket), and Bamboo. • Access to native cloud services and resources provided by the CSP. Managed Hosting Environment • Cloud account provisioning and invoicing, with transparency on service utilization with FinOps dashboards. • Remote Desktop Services. • Operating System (OS) level patching performed as part of monthly patch deployments. • Vulnerability scanning: OS, Databases, and Web application. • Identification, prioritization, and mitigation of OS and Database level vulnerabilities. • Configuration management for OS and Databases . • Intrusion Prevention Services (IPS); VPN; Web Application Firewall (WAF); Direct connection with Treasury T-NET network. • Anti-Virus and Host Based Firewall. • Endpoint Detection and Response. • Audit log ingestion and monitoring (OS Level, Database, and CSP). • Directory services, accounts and permission management provided through Microsoft Active Directory. • IAM policies, groups, roles, preconfigured to enforce identify guardrails. • IAM audit trails and change monitoring that produce alerts and notifications to predetermined set of stakeholders. • Single Sign-On with connection to TCloud Active Directory. • Monitoring of network ingress and egress traffic. • Preconfigured networking resources, with audit trails and change monitoring that produce alerts and notifications to predetermined set of stakeholders. • Unified cloud security platform that includes vulnerability management, compliance and posture management, workload protection, and container security. • Disaster recovery and Contingency Planning - Backup and restore. • Disaster recovery and Contingency Planning - Different availability zones for resiliency. • Security incident and response monitoring and coordination with appropriate stakeholders. • Management, configuration, and provisioning of Atlassian software suite available for customers- JIRA, Confluence, Stash (BitBucket), and Bamboo. • Access to native cloud services and resources provided by each CSP.

What FedXchange has recorded

No change since FedXchange began following it on April 14, 2026. Each change of stage, impact level, or number of authorizations appears here.