Schellman’s Marci Womack Appointed to the U.S. GSA’s Federal Secure Cloud Advisory Committee
The appointment demonstrates the firm’s commitment to improving the adoption of secure cloud-computing products and services.
TAMPA, Fla.— May 15, 2023—As one of the largest and most experienced third-party assessment organizations (3PAOs) under the Federal Risk and Authorization Management Program (FedRAMP), Schellman is proud to announce that its own Marci Womack has been appointed to the U.S. General Services Administration's (GSA) Federal Secure Cloud Advisory Committee (FSCAC) as the representative member for 3PAOs.
Since its inception, FedRAMP has worked together with industry and government to evolve the program—the newly formed FSCAC will formalize this collaboration as a part of the program and continue the trajectory of growth in a way that reduces the overall burden of FedRAMP on stakeholders.
As the first woman to receive an appointment to this committee, Womack will begin her 2-year term on May 15, 2023, during which she will use both the breadth of her expertise and her perspective as an independent assessor to provide recommendations on technical, financial, programmatic, and operational matters regarding the adoption of secure cloud-computing products and services.
"I am honored to represent Schellman on the FSCAC," said Womack. "Schellman's extensive experience as a 3PAO under FedRAMP gives us both a unique proficiency and the ability to provide valuable insights into the security and adoption of cloud computing in the public sector. I look forward to working with my fellow members to promote the continued evolution of this impactful program that is facilitated by direct communication and collaboration among the stakeholder community."
In total, the FSCAC is comprised of 15 participants from the public and private sectors that includes five representatives from cloud services companies, two members from small businesses, and just one from an independent assessment organization under FedRAMP.
As that representative on behalf of Schellman, Marci will work with the others to improve authorization processes across the FedRAMP Program Management Office (PMO) and agencies, collect feedback on cloud service provider compliance and implementation of FedRAMP requirements, evaluate and promote innovative technologies and approaches like the Open Security Controls Assessment Language (OSCAL), and facilitate communication and collaboration among the FedRAMP stakeholder community.
"Schellman is thrilled to have Marci appointed to the FSCAC," said Avani Desai, CEO of Schellman. "As one of the largest 3PAOs in FedRAMP, we have the expertise and experience to provide valuable insights into the adoption of secure cloud-computing products and services. We are proud that Marci will be representing our fellow 3PAOs on the committee and are confident that her contributions will be instrumental in improving the U.S. government’s adoption of secure cloud-computing products and services."
Marci Womack is a Director in Schellman’s Federal Practice and oversees both the firm’s established FedRAMP assessment program and its emerging CMMC assessment program. Before joining Schellman in 2016 as a senior associate, she worked both as a federal contractor implementing and assessing federal cybersecurity programs and as an FFIEC/GLBA security controls auditor and consultant. Marci has over 10 years of information security experience across various industries and holds multiple cybersecurity certifications, making her a valuable addition to FSCAC and an excellent representative of Schellman.
About Schellman
Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.