GSA Details Federal Cloud Security Program
The General Services Administration on Tuesday released extensive new details on FedRAMP, a program the Obama administration hopes will accelerate the adoption of cloud computing and cut security costs.The GSA-led FedRAMP is a soon-to-be-mandatory government-wide program that standardizes the government's approach to authorizing cloud services for use by federal agencies and monitoring those services to ensure that they continue to meet federal cybersecurity requirements.
More Government Insights
Webcasts
- The ABC's of Cloud Computing in the Midmarket
- Single Source of Truth for Managing Critical Assets Application Consolidation across Public Sector Organizations
White Papers
More >>Reports
- Research: Federal Government Cloud Computing Survey
- SaaS 2011: Adoption Soars, Yet Deployment Concerns Linger
Once a service goes through the initial FedRAMP authorization process, it gets a stamp of approval that any agency can use to sign off on the service's ability to meet federal security requirements. This is much more efficient and standardized than the historic approach to security authorization, which required each agency to do its own authorization. Federal CIO Steven VanRoekel has estimated that FedRAMP could save federal agencies between 30% and 40% on their security assessments and cloud procurement processes.
[ Why aren't federal IT pros sold on cloud computing? See Cloud Security, Costs Concern Federal IT Pros. ]
According to the 47-page concept of operations document, popular collaboration and infrastructure-as-a-service tools will be the first applications to run through the FedRAMP authorization process. At an event hosted by tech industry group TechAmerica on Wednesday, GSA officials said that they will prioritize services where there are already existing contracts.
The FedRAMP authorization process will include: -- a joint authorization board, consisting of the Department of Defense, Department of Homeland Security, and GSA, which will do initial security assessments and define and update baseline security controls; -- third-party assessment organizations, which will carry out outsourced assessments; -- and an incident-response coordinator in DHS, which will continuously monitor security compliance and responses to security incidents. A program management office at GSA will oversee the whole process.
GSA said Wednesday that the first set of third-party accreditors will be announced by April. Although the joint authorization board or third-party accreditors will be in charge of initial assessments themselves, each agency still will have to sign off on their own to grant the final security green light to each cloud service they decide to use.
FedRAMP's security standards were published in January. During the rest of this fiscal year, according to the document, the FedRAMP team will formally launch FedRAMP into operation, draw up an initial list of third-party assessors, and finalize an initial set of authorizations. The program will continue to ramp up into next fiscal year.
Although federal officials have described FedRAMP as a mandatory process, GSA officials said Wednesday that there are no plans to write FedRAMP requirements into official federal acquisition regulations. Instead, GSA is working on developing standard contractual language that agencies can use to make FedRAMP compliance a contractual requirement, and could issue stand-alone policy mandating agency use of FedRAMP.
How 10 federal agencies are tapping the power of cloud computing--without compromising security. Also in the new, all-digital InformationWeek Government supplement: To judge the success of the OMB's IT reform efforts, we need concrete numbers on cost savings and returns. Download our Cloud In Action issue of InformationWeek Government now. (Free registration required.)
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Subscribe to RSSResource Links
Related Webcasts
- The ABC's of Cloud Computing in the Midmarket
- Reliable Information for Actionable Insights
- The view is better up here: breaking through barriers to Cloud
- Supporting an Enterprise-wide Data Archive and Retention Strategy
- Single Source of Truth for Managing Critical Assets Application Consolidation across Public Sector Organizations
This Week's Issue
Free Print Subscription
SubscribeCurrent Healthcare Issue
- InformationWeek Healthcare CIO 25: Our second annual honor roll of the health IT leaders driving healthcare's transformation.
- EHR Unreadiness: Only a small percentage of physicians planning to apply for Meaningful Use funds have e-health record systems capable of achieving most of the requirements. .
- And much more!
- Read the Current Issue
Related Whitepapers
- Unleashing Cloud Performance
- Advanced Case Management: Making its Mark on Key Government Sectors
- The Creating value in the Public Sector: intelligent project selection in the US federal government
- Improve Business Performance in a Project-Intensive World
- Get started with cloud through the right business-based IT strategy
Featured Whitepaper
In this white paper, Tripwire discusses strategies for defending cyber threats that include monitoring security status of systems throughout the enterprise, detecting threats to sensitive data, and responding to threats in real-time.
Learn More













