Standards

NIST seeks comment on draft cloud security guidelines

NIST outline

This NIST graphic, taken from the new draft security reference architecture, illustrates the capabilities of cloud computing in various contexts.

The National Institute of Standards and Technology (NIST) has published a draft document outlining security for cloud computing in the federal government.

In 2010, then-Federal CIO Vivek Kundra asked NIST to help accelerate the adoption of cloud computing. NIST released its "Cloud Computing Reference Architecture" the next year, which created a standard framework for cloud computing in the federal government.

The newly published draft, the "NIST Cloud Computing Security Reference Architecture," is a hefty supplement to that document. It outlines a comprehensive security model for cloud computing at the federal level and provides a layer of security to the "NIST Cloud Computing Reference Architecture."

It was written by the NIST Cloud Computing Public Security Working Group as part of a priority action plan set out in NIST's roadmap for cloud computing technology.

"The document's objective is to demystify the process of selecting cloud-based services that best address an agency's requirements in the most secure and efficient manner," said Michaela Iorga, NIST Cloud Computing Security Working Group chair, in an announcement of the new draft.

The "NIST Cloud Computing Security Reference Architecture" introduces a cloud-based risk management framework, which will help federal organizations create a security plan based on how sensitive an organization's information is and its level of risk tolerance.

The draft also includes a case study that follows an agency's implementation of the Risk Management Framework in deploying a typical application to the cloud.

"The Risk Management Framework has to be adapted when applying the risk-based approach to applications or systems migrated to the cloud because the implementation, assessment, authorization and monitoring of selected security controls may fall under the responsibility of different cloud 'actors;' for example, consumer, service provider or broker," said Iorga.

The draft is now online, and the agency is seeking public comment. Feedback should be sent to Iorga at michaela.iorga@nist.gov by July 12.



Video Bonus: Vivek Kundra, speaking in 2010 at a NIST-organized forum on cloud computing.

About the Author

Natalie Lauri is an editorial fellow at FCW. Connect with her on Twitter: @Nat_Lauri.

The Fed 100

Read the profiles of all this year's winners.

Featured

  • Then-presidential candidate Donald Trump at a 2016 campaign event. Image: Shutterstock

    'Buy American' order puts procurement in the spotlight

    Some IT contractors are worried that the "buy American" executive order from President Trump could squeeze key innovators out of the market.

  • OMB chief Mick Mulvaney, shown here in as a member of Congress in 2013. (Photo credit Gage Skidmore/Flickr)

    White House taps old policies for new government makeover

    New guidance from OMB advises agencies to use shared services, GWACs and federal schedules for acquisition, and to leverage IT wherever possible in restructuring plans.

  • Shutterstock image (by Everett Historical): aerial of the Pentagon.

    What DOD's next CIO will have to deal with

    It could be months before the Defense Department has a new CIO, and he or she will face a host of organizational and operational challenges from Day One

  • USAF Gen. John Hyten

    General: Cyber Command needs new platform before NSA split

    U.S. Cyber Command should be elevated to a full combatant command as soon as possible, the head of Strategic Command told Congress, but it cannot be separated from the NSA until it has its own cyber platform.

  • Image from Shutterstock.

    DLA goes virtual

    The Defense Logistics Agency is in the midst of an ambitious campaign to eliminate its IT infrastructure and transition to using exclusively shared, hosted and virtual services.

  • Fed 100 logo

    The 2017 Federal 100

    The women and men who make up this year's Fed 100 are proof positive of what one person can make possibile in federal IT. Read on to learn more about each and every winner's accomplishments.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group