Cloud

DOD updates cloud requirements guide

cloud security

Defense Department IT officials have released an update to a cloud security requirements guide that governs commercial cloud offerings for DOD missions up to the secret level.

The SRG helps determine whether defense officials grant commercial cloud firms a provisional authorization to host DOD data. This is the second iteration of the SRG, and it is based on feedback from the first version, released in January 2015.

The Defense Information Systems Agency and the DOD CIO's office -- the two organizations that issue the SRG -- are still interested in feedback on the document.

"This ongoing public comment period will allow our mission partners to offer changes as they become necessary," said Robert Vietmeyer, associate director for cloud computing and agile development in the DOD CIO's office. "This is in direct support of the DOD CIO's vision of 'agile policy development.'"

DISA also published a history of revisions made to the SRG to track changes to the guidelines. For example, officials removed a section on classified data beyond the Level 6 secret level from the first version of the SRG to "alleviate confusion and any potential inaccuracy."

The SRG is part of an ongoing effort by Pentagon IT leaders to better define what cloud computing means for defense missions. That definition can affect how cloud services are implemented. A DOD inspector general audit conducted from December 2014 to October 2015 found that the lack of a standard definition for cloud computing across the department was undercutting the CIO's effort to deploy cloud services.

About the Author

Sean Lyngaas is an FCW staff writer covering defense, cybersecurity and intelligence issues. Prior to joining FCW, he was a reporter and editor at Smart Grid Today, where he covered everything from cyber vulnerabilities in the U.S. electric grid to the national energy policies of Britain and Mexico. His reporting on a range of global issues has appeared in publications such as The Atlantic, The Economist, The Washington Diplomat and The Washington Post.

Lyngaas is an active member of the National Press Club, where he served as chairman of the Young Members Committee. He earned his M.A. in international affairs from The Fletcher School of Law and Diplomacy at Tufts University, and his B.A. in public policy from Duke University.

Click here for previous articles by Lyngaas, or connect with him on Twitter: @snlyngaas.


Featured

  • FCW PERSPECTIVES
    sensor network (agsandrew/Shutterstock.com)

    Are agencies really ready for EIS?

    The telecom contract has the potential to reinvent IT infrastructure, but finding the bandwidth to take full advantage could prove difficult.

  • People
    Dave Powner, GAO

    Dave Powner audits the state of federal IT

    The GAO director of information technology issues is leaving government after 16 years. On his way out the door, Dave Powner details how far govtech has come in the past two decades and flags the most critical issues he sees facing federal IT leaders.

  • FCW Illustration.  Original Images: Shutterstock, Airbnb

    Should federal contracting be more like Airbnb?

    Steve Kelman believes a lighter touch and a bit more trust could transform today's compliance culture.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.