Follow Feds To The Cloud

Uncle Sam is a leader in the secure use of cloud services. Here’s what FedRAMP and FISMA can teach you.

Michael A. Davis, CTO of CounterTack

April 26, 2013

4 Min Read
InformationWeek logo in a gray background | InformationWeek

InformationWeek Green -  April 29, 2013

InformationWeek Green - April 29, 2013

InformationWeek Green

InformationWeek Green


Download the entire April 29, 2013, issue of InformationWeek, distributed in an all-digital format (registration required).


Follow The Feds

Follow The Feds

It's not often that IT teams charged with new projects and initiatives say, "Let's look at how the feds are doing things." The U.S. government's IT systems are seen as slow, archaic and overly complex -- think the Veterans Affairs Department's huge claims backlog and the sorry state of the National Instant Criminal Background Check System, which handles only 6% of requests electronically. But thanks to the "Cloud First" and open data sharing initiatives that former federal CIO Vivek Kundra mandated, the government is an innovator when it comes to cloud computing and data security.

The benefits of that work aren't limited to government agencies. Businesses can take advantage of it, too, particularly with regard to security issues. Our 2013 InformationWeek State of Cloud Computing Survey of nearly 450 business technology professionals at companies with 50 or more employees shows there's a real need to address security concerns.

On one hand, the percentage of respondents predicting their companies will use few or no IT cloud services has dropped seven points since our 2012 survey, to 31%. But just 18% populate the middle ground -- with a quarter to half of their services in the cloud -- even though that's what most CIOs we work say is the sweet spot for cloud uptake. Security is the top concern, specifically concerns about defects in cloud technology and the potential leakage of proprietary or customer data. Much lesser concerns are performance, vendor viability and vendor lock-in.

Enter Uncle Sam

The Federal Risk and Authorization Management Program, or FedRAMP, provides a framework for certifying the security of federal government cloud environments. To participate, a cloud service provider must hire an independent, government-certified auditor to verify that the provider complies with the standards framework. Once certified, fed agencies can buy services from the provider without having to go through a security review process.

Research: 2013 State Of Cloud Computing

Report Cover

Report Cover

Our report on the state of cloud computing is free with registration. This report includes 27 pages of action-oriented analysis, packed with 22 charts.

What you'll find:

  • Why some are still taking a cautious approach to the cloud

  • The problem with service-level agreements

Get This And All Our Reports

FedRAMP is being driven by the General Services Administration in collaboration with the Department of Defense, Office of Management and Budget, Federal CIO Council and other agencies. A rigorous governance structure was necessary to support government-wide adoption, and that's one of the reasons businesses are looking to the feds as a strong cloud computing reference model.

FedRAMP's focus on trust verification is a big reason it will reverberate beyond the government. Within five years, FedRAMP-mandated controls will be the rule, not the exception, in both the private and public sectors.

FedRAMP's real beauty is that it looks at use cases, not just providers. For example, if high-value data is involved in a project, then no cloud provider can be used, no matter how well vetted it is.

Translated to the private sector, this approach takes the heat off IT. You won't have to be the no police or make a series of one-off decisions. Instead, you can focus on a more important issue: the movement of data and processes to the cloud.

To read the rest of the article,
download the April 29, 2013, issue of InformationWeek.

Read more about:

20132013

About the Author

Michael A. Davis

CTO of CounterTack

Michael A. Davis has been privileged to help shape and educate the globalcommunity on the evolution of IT security. His portfolio of clients includes international corporations such as AT&T, Sears, and Exelon as well as the U.S. Department of Defense. Davis's early embrace of entrepreneurship earned him a spot on BusinessWeek's "Top 25 Under 25"
list, recognizing his launch of IT security consulting firm Savid Technologies, one of the fastest-growing companies of its decade. He has a passion for educating others and, as a contributing author for the *Hacking Exposed* books, has become a keynote speaker at dozens of conferences and symposiums worldwide.

Davis serves as CTO of CounterTack, provider of an endpoint security platform delivering real-time cyberthreat detection and forensics. He joined the company because he recognized that the battle is moving to the endpoint and that conventional IT security technologies can't protect enterprises. Rather, he saw a need to deliver to the community continuous attack monitoring backed by automated threat analysis.

Davis brings a solid background in IT threat assessment and protection to his latest posting, having been Senior Manager Global Threats for McAfee prior to launching Savid, which was acquired by External IT. Aside from his work advancing cybersecurity, Davis writes for industry publications including InformationWeek and Dark Reading. Additionally, he has been a partner in a number of diverse entrepreneurial startups; held a leadership position at 3Com; managed two Internet service providers; and recently served as President/CEO of the InClaro Group, a firm providing information security advisory and consulting services based on a unique risk assessment methodology.

Never Miss a Beat: Get a snapshot of the issues affecting the IT industry straight to your inbox.

You May Also Like


More Insights