Access and Feeds

Cloud Computing: GSA Pushes Forward Government Adoption of the Cloud with FedRaMP

By Dick Weisinger

In January, the US Federal government issued a comprehensive list of 168 security control requirements in 16 categories that cloud providers must first comply with before being able to provide services to any Federal agency.   The requirements cover, for example,  the specifics of software upgrades and backups, smartphone access, and security issues.  While that list of requirements is lengthy, the good news for vendors is that once they are able to prove compliance with those requirements, they then become eligible to sell their services to any federal agency.  In this way, there is just a single test that must be passed in order to become eligible to sell cloud services into the government.

The requirements were issued by the Federal Risk and Authorization Management Program (FedRAMP), part of the US General Services Administration (GSA).  The charter of the group is to provide a standardized approach in the government to security assessment, authorization, and continuous monitoring for cloud products and services.  By creating a “do once, use many times” framework, they expect to be able to save both money and time by centralizing the approval process and avoiding redundant security assessments that would otherwise would have to be made by each individual agency in the government.  The expectations are that the process can speed the process of getting federal agencies to start using cloud services.

Department of Homeland Security Chief Information Officer Richard Spires wrote that “FedRAMP’s unified risk management process will evaluate IT services offered by vendors on behalf of federal agencies, saving agencies from conducting their own risk management programs.  This baseline serves all federal agencies and [cloud service providers], to which additional controls may be added by agencies to meet specific requirements.”

The GSA is expected to specify the details of the compliance audit procedure by February 8th.  A “joint authorization board” (JAB) made up of security experts from the Department of Homeland Security, Pentagon and the GSA is expected to be involved in evaluating cloud products.  The JAB has said that they will publish three documents over the next six months to further clarify details about each of the requirements and how they will be tested.  Those publications are:

  • System Security Plan will detail the requirements for each security control of a cloud computing environment
  • Security Assessment Plan will detail how each control implementation will be assessed and tested to make sure that it meets the requirements
  • Security Assessment Report will detail recommendations related to the security control assessments detailed in the Security Assessment Plan

FedRaMP is a good sign that the federal government is serious about cloud computing.   The speed with which the government is moving on this also comes as somewhat of a surprise.  Historically, the government has been a late adopter of technology, but in this case they are positioning themselves to become a model for businesses.

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*