Can 18F's Cloud.gov pass FedRAMP review?
When the Federal Risk and Authorization Management Program unveiled its new "FedRAMP Accelerated" process in March, 18F's Cloud.gov project was one of three test drivers for the new approach.
More than three months later, Cloud.gov is still not through all the hoops. But the General Services Administration-run cloud service provider was declared FedRAMP Ready in June, and on July 18 four members of 18F posted a lengthy update on the progress to date. Final approval from the FedRAMP Joint Authorization Board, they wrote, is expected in November.
Cloud.gov is a platform-as-a-service offering that aims to handle "shared technical and policy requirements common to all federal government systems," according to the 18F post. It runs on commercial infrastructure, and one of the team's next steps is migrating Cloud.gov to Amazon Web Services' GovCloud. Also on the list is expanding the security incident response plan.
And while one of the goals of the new FedRAMP processes was to reduce the emphasis on up-front paperwork, Cloud.gov is deep into documentation efforts now that it's before the Joint Authorization Board.
18F built its own "Compliance Masonry tool," and is using that for Cloud.gov "so that we can collaborate on required documentation in a structured way rather than wrangling a multi-hundred-page Word document." The goal, the blog authors wrote, is to make the materials "easily reusable as part of compliance documentation" for agencies that choose to run services on Cloud.gov.
A November FedRAMP authorization for Cloud.gov would put mean a roughly eight-month process -- far better than the nine to 18 months most CSPs have averaged, but not quite the three-to-six-month turnaround that FedRAMP Director Matt Goodrich has said is the goal.
The pilot projects for FedRAMP Accelerated -- in addition to the Cloud.gov team, Microsoft and Unisys have also been helping to test the new process -- were expected to take a bit longer, of course. But there might soon be legislative pressure to accelerate further: The MOVE IT Act, introduced on June 14 in both the House and Senate, calls for "maximum time limits for the completion of authorizations ... not to exceed six months."
Troy K. Schneider is editor-in-chief of FCW and GCN, as well as General Manager of Public Sector 360.
Prior to joining 1105 Media in 2012, Schneider was the New America Foundation’s Director of Media & Technology, and before that was Managing Director for Electronic Publishing at the Atlantic Media Company. The founding editor of NationalJournal.com, Schneider also helped launch the political site PoliticsNow.com in the mid-1990s, and worked on the earliest online efforts of the Los Angeles Times and Newsday. He began his career in print journalism, and has written for a wide range of publications, including The New York Times, WashingtonPost.com, Slate, Politico, National Journal, Governing, and many of the other titles listed above.
Schneider is a graduate of Indiana University, where his emphases were journalism, business and religious studies.
Click here for previous articles by Schneider, or connect with him on Twitter: @troyschneider.