Security-minded program could aid cloud transition

If approved, FedRAMP would develop a common core of security requirements for cloud services

An interagency working group has developed a program to help agencies assess and manage the risks associated with moving applications to a cloud computing environment.

The Federal Risk and Authorization Management Program, developed by the Cloud Computing Advisory Council, will create governmentwide security requirements for cloud services based on the latest guidance from the National Institute of Standards and Technology. FedRAMP also will provide a common certification and accreditation process for security systems.

In an interview with GovInfoSecurity.com, the vice chairman of the council, NIST’s Peter Mell, said the organization has sent the details of the program to agencies, and after they give their blessing, the program will move into the testing phase.

Currently, it’s up to each agency to make sure that its cloud-based applications and systems are secure enough to store and manage government data.

“That leads to longer-than-necessary lead times to adoption and decisions not to adopt because the certification and accreditation process can be tedious,” writes J. Nicholas Hoover at InformationWeek.

A centralized process also should make it easier for industry vendors to develop products by providing them with a common set of requirements to meet, Hoover said.

About the Author

John Monroe is Senior Events Editor for the 1105 Public Sector Media Group, where he is responsible for overseeing the development of content for print and online content, as well as events. John has more than 20 years of experience covering the information technology field. Most recently he served as Editor-in-Chief of Federal Computer Week. Previously, he served as editor of three sister publications: civic.com, which covered the state and local government IT market, Government Health IT, and Defense Systems.

The Fed 100

Save the date for 28th annual Federal 100 Awards Gala.

Featured

  • computer network

    How Einstein changes the way government does business

    The Department of Commerce is revising its confidentiality agreement for statistical data survey respondents to reflect the fact that the Department of Homeland Security could see some of that data if it is captured by the Einstein system.

  • Defense Secretary Jim Mattis. Army photo by Monica King. Jan. 26, 2017.

    Mattis mulls consolidation in IT, cyber

    In a Feb. 17 memo, Defense Secretary Jim Mattis told senior leadership to establish teams to look for duplication across the armed services in business operations, including in IT and cybersecurity.

  • Image from Shutterstock.com

    DHS vague on rules for election aid, say states

    State election officials had more questions than answers after a Department of Homeland Security presentation on the designation of election systems as critical U.S. infrastructure.

  • Org Chart Stock Art - Shutterstock

    How the hiring freeze targets millennials

    The government desperately needs younger talent to replace an aging workforce, and experts say that a freeze on hiring doesn't help.

  • Shutterstock image: healthcare digital interface.

    VA moves ahead with homegrown scheduling IT

    The Department of Veterans Affairs will test an internally developed scheduling module at primary care sites nationwide to see if it's ready to service the entire agency.

  • Shutterstock images (honglouwawa & 0beron): Bitcoin image overlay replaced with a dollar sign on a hardware circuit.

    MGT Act poised for a comeback

    After missing in the last Congress, drafters of a bill to encourage cloud adoption are looking for a new plan.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group