How much cloud is too much cloud?
- By Colby Hochmuth
- Feb 26, 2015
What: "Cloud Adoption & Risk in Government Report," by Skyhigh Networks
Why: In order for government to secure all the cloud services it offers and meet FISMA and FedRAMP requirements, it first needs to know how many cloud services are actually coming into the organization.
The average public sector organization uses 721 cloud services. A recent study found that only one third of federal agencies met a June 2014 deadline to meet FedRAMP security guidelines -- but that report didn’t cover what cloud services employees are bringing to work with them, known as shadow IT.
Skyhigh Networks’ fourth quarter 2014 report looked at what cloud services are most prevalent in government organizations and the risks associated with such services.
The top categories of cloud services are: collaboration cloud services (like Microsoft Office 365, Gmail, etc.), file-sharing services (Box, Dropbox, Google Drive, etc.), development services (GitHub, SourceForge, etc.) and social media services (like Facebook, LinkedIn, etc.).
The report also found that agencies increased their spending on security for cloud services over the past year as companies expanded their capabilities.
About 1,459 cloud services (17 percent) offer multi-factor authentication, compared with 705 services last year, and 1,082 (11 percent) encrypt data at rest, compared with 470 services last year.
While agencies are taking measures to block access to non-secure services via a firewall or proxy, the report found that there is a cloud enforcement gap for how effectively agencies are blocking these services.
For example, Dropbox’s enforcement gap is 64 percent -- cloud services think their block rate is 80 percent, when in fact it is only 16 percent. Dropbox’s enforcement gap is closely followed by Instagram (45 percent), and Apple iCloud (42 percent).
Verbatim: "In some categories, the fragmentation of cloud services impedes collaboration across teams, introduces friction and creates cost inefficiencies. In addition, employees may not fully understand the risk of cloud services before using them in the workplace."
Read the full report here.
Colby Hochmuth is a former staff writer for FCW.