Critical Read

How much cloud is too much cloud?

Shutterstock image (by ra2studio): young businessman looking at a cloud concept wall.

(Image: ra2studio / Shutterstock)

What: "Cloud Adoption & Risk in Government Report," by Skyhigh Networks

Why: In order for government to secure all the cloud services it offers and meet FISMA and FedRAMP requirements, it first needs to know how many cloud services are actually coming into the organization.

The average public sector organization uses 721 cloud services. A recent study found that only one third of federal agencies met a June 2014 deadline to meet FedRAMP security guidelines -- but that report didn’t cover what cloud services employees are bringing to work with them, known as shadow IT.

Skyhigh Networks’ fourth quarter 2014 report looked at what cloud services are most prevalent in government organizations and the risks associated with such services.

The top categories of cloud services are: collaboration cloud services (like Microsoft Office 365, Gmail, etc.), file-sharing services (Box, Dropbox, Google Drive, etc.), development services (GitHub, SourceForge, etc.) and social media services (like Facebook, LinkedIn, etc.).

The report also found that agencies increased their spending on security for cloud services over the past year as companies expanded their capabilities.

About 1,459 cloud services (17 percent) offer multi-factor authentication, compared with 705 services last year, and 1,082 (11 percent) encrypt data at rest, compared with 470 services last year.

While agencies are taking measures to block access to non-secure services via a firewall or proxy, the report found that there is a cloud enforcement gap for how effectively agencies are blocking these services.

For example, Dropbox’s enforcement gap is 64 percent -- cloud services think their block rate is 80 percent, when in fact it is only 16 percent. Dropbox’s enforcement gap is closely followed by Instagram (45 percent), and Apple iCloud (42 percent).

Verbatim: "In some categories, the fragmentation of cloud services impedes collaboration across teams, introduces friction and creates cost inefficiencies. In addition, employees may not fully understand the risk of cloud services before using them in the workplace." 

Read the full report here.

About the Author

Colby Hochmuth is a former staff writer for FCW.

Featured

  • Cybersecurity

    DHS floats 'collective defense' model for cybersecurity

    Homeland Security Secretary Kirstjen Nielsen wants her department to have a more direct role in defending the private sector and critical infrastructure entities from cyberthreats.

  • Defense
    Defense Secretary James Mattis testifies at an April 12 hearing of the House Armed Services Committee.

    Mattis: Cloud deal not tailored for Amazon

    On Capitol Hill, Defense Secretary Jim Mattis sought to quell "rumors" that the Pentagon's planned single-award cloud acquisition was designed with Amazon Web Services in mind.

  • Census
    shutterstock image

    2020 Census to include citizenship question

    The Department of Commerce is breaking with recent practice and restoring a question about respondent citizenship last used in 1950, despite being urged not to by former Census directors and outside experts.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.