Cloud
News
4/26/2013
02:20 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Follow Feds To The Cloud

Uncle Sam is a leader in the secure use of cloud services. Here’s what FedRAMP and FISMA can teach you.

InformationWeek Green -  April 29, 2013 InformationWeek Green
Download the entire April 29, 2013, issue of InformationWeek, distributed in an all-digital format (registration required).


Follow The Feds

It's not often that IT teams charged with new projects and initiatives say, "Let's look at how the feds are doing things." The U.S. government's IT systems are seen as slow, archaic and overly complex -- think the Veterans Affairs Department's huge claims backlog and the sorry state of the National Instant Criminal Background Check System, which handles only 6% of requests electronically. But thanks to the "Cloud First" and open data sharing initiatives that former federal CIO Vivek Kundra mandated, the government is an innovator when it comes to cloud computing and data security.

The benefits of that work aren't limited to government agencies. Businesses can take advantage of it, too, particularly with regard to security issues. Our 2013 InformationWeek State of Cloud Computing Survey of nearly 450 business technology professionals at companies with 50 or more employees shows there's a real need to address security concerns.

On one hand, the percentage of respondents predicting their companies will use few or no IT cloud services has dropped seven points since our 2012 survey, to 31%. But just 18% populate the middle ground -- with a quarter to half of their services in the cloud -- even though that's what most CIOs we work say is the sweet spot for cloud uptake. Security is the top concern, specifically concerns about defects in cloud technology and the potential leakage of proprietary or customer data. Much lesser concerns are performance, vendor viability and vendor lock-in.

Enter Uncle Sam

The Federal Risk and Authorization Management Program, or FedRAMP, provides a framework for certifying the security of federal government cloud environments. To participate, a cloud service provider must hire an independent, government-certified auditor to verify that the provider complies with the standards framework. Once certified, fed agencies can buy services from the provider without having to go through a security review process.

Report Cover
Our report on the state of cloud computing is free with registration. This report includes 27 pages of action-oriented analysis, packed with 22 charts.

What you'll find:
  • Why some are still taking a cautious approach to the cloud
  • The problem with service-level agreements
Get This And All Our Reports

FedRAMP is being driven by the General Services Administration in collaboration with the Department of Defense, Office of Management and Budget, Federal CIO Council and other agencies. A rigorous governance structure was necessary to support government-wide adoption, and that's one of the reasons businesses are looking to the feds as a strong cloud computing reference model.

FedRAMP's focus on trust verification is a big reason it will reverberate beyond the government. Within five years, FedRAMP-mandated controls will be the rule, not the exception, in both the private and public sectors.

FedRAMP's real beauty is that it looks at use cases, not just providers. For example, if high-value data is involved in a project, then no cloud provider can be used, no matter how well vetted it is.

Translated to the private sector, this approach takes the heat off IT. You won't have to be the no police or make a series of one-off decisions. Instead, you can focus on a more important issue: the movement of data and processes to the cloud.

To read the rest of the article,
download the April 29, 2013, issue of InformationWeek.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
John Foley
50%
50%
John Foley,
User Rank: Apprentice
4/29/2013 | 8:35:34 PM
re: Follow Feds To The Cloud
One of the primary objectives of FedRAMP is to vet commercial cloud services for use by government agencies. Once a cloud service goes through the process and receives the FedRAMP stamp of approval, it becomes (theoretically) faster and easier for other agencies to subscribe to that cloud service knowing it is bonafide and up to federal requirements. It makes sense that businesses can benefit from all of that front-end scrutiny, as well.
2014 Next-Gen WAN Survey
2014 Next-Gen WAN Survey
While 68% say demand for WAN bandwidth will increase, just 15% are in the process of bringing new services or more capacity online now. For 26%, cost is the problem. Enter vendors from Aryaka to Cisco to Pertino, all looking to use cloud to transform how IT delivers wide-area connectivity.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest, Nov. 10, 2014
Just 30% of respondents to our new survey say their companies are very or extremely effective at identifying critical data and analyzing it to make decisions, down from 42% in 2013. What gives?
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Join us for a roundup of the top stories on InformationWeek.com for the week of November 16, 2014.
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.