Security-minded program could aid cloud transition

If approved, FedRAMP would develop a common core of security requirements for cloud services

An interagency working group has developed a program to help agencies assess and manage the risks associated with moving applications to a cloud computing environment.

The Federal Risk and Authorization Management Program, developed by the Cloud Computing Advisory Council, will create governmentwide security requirements for cloud services based on the latest guidance from the National Institute of Standards and Technology. FedRAMP also will provide a common certification and accreditation process for security systems.

In an interview with GovInfoSecurity.com, the vice chairman of the council, NIST’s Peter Mell, said the organization has sent the details of the program to agencies, and after they give their blessing, the program will move into the testing phase.

Currently, it’s up to each agency to make sure that its cloud-based applications and systems are secure enough to store and manage government data.

“That leads to longer-than-necessary lead times to adoption and decisions not to adopt because the certification and accreditation process can be tedious,” writes J. Nicholas Hoover at InformationWeek.

A centralized process also should make it easier for industry vendors to develop products by providing them with a common set of requirements to meet, Hoover said.

About the Author

John Monroe is Senior Events Editor for the 1105 Public Sector Media Group, where he is responsible for overseeing the development of content for print and online content, as well as events. John has more than 20 years of experience covering the information technology field. Most recently he served as Editor-in-Chief of Federal Computer Week. Previously, he served as editor of three sister publications: civic.com, which covered the state and local government IT market, Government Health IT, and Defense Systems.

The Fed 100

Read the profiles of all this year's winners.

Featured

  • Shutterstock image (by wk1003mike): cloud system fracture.

    Does the IRS have a cloud strategy?

    Congress and watchdog agencies have dinged the IRS for lacking an enterprise cloud strategy seven years after it became the official policy of the U.S. government.

  • Shutterstock image: illuminated connections between devices.

    Who won what in EIS

    The General Services Administration posted detailed data on how the $50 billion Enterprise Infrastructure Solutions contract might be divvied up.

  • Wikimedia Image: U.S. Cyber Command logo.

    Trump elevates CyberCom to combatant command status

    The White House announced a long-planned move to elevate Cyber Command to the status of a full combatant command.

  • Photo credit: John Roman Images / Shutterstock.com

    Verizon plans FirstNet rival

    Verizon says it will carve a dedicated network out of its extensive national 4G LTE network for first responders, in competition with FirstNet.

  • AI concept art

    Can AI tools replace feds?

    The Heritage Foundation is recommending that hundreds of thousands of federal jobs be replaced by automation as part of a larger government reorganization strategy.

  • DOD Common Access Cards

    DOD pushes toward CAC replacement

    Defense officials hope the Common Access Card's days are numbered as they continue to test new identity management solutions.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group