Few cloud vendors expected to receive initial FedRAMP assessments
Numerous U.S. government agencies are adopting cloud computing solutions to secure critical data, reduce IT costs and improve efficiency. In December, the General Services Administration (GSA) launched the Federal Risk and Authorization Management Program (FedRAMP), a government-wide policy developed to standardize agency adoption of cloud services through security assessment and authorization.
Although FedRAMP has yet to be put into effect, its potential impact on government IT departments and federal CIOs is beginning to take shape. In February, the GSA announced that cloud vendors could submit services for assessment without first having a contract with an agency. However, according to a recent Federal Times report, no more than 20 cloud providers are expected to receive initial security assessments for federal use when FedRAMP is officially implemented in June.
"It is not going to be a situation where we will be drowning in FedRAMP applications," Dave McClure of GSA's Office of Citizen Services and Innovative Technologies told the news source. "We want to roll this out very cautiously and carefully, [and] make sure it works."
McClure said he predicts six to 20 vendors will send cloud products and services through FedRAMP in the inaugural six to eight months, with providers on the GSA's impending Email-as-a-Service contract and current Infrastructure-as-a-Service contract having first priority. Furthermore, McClure expects FedRAMP to become a sustaining program by 2014, with all cloud products eventually going through the assessment and authorization process.
FedRAMP is a major part of the U.S. government's desire to promote IT solutions that reduce IT costs, increase innovation and enable agencies and businesses to better prepare for future technologies. Despite several agencies already running cloud-based applications, infrastructure and other services to accomplish these goals, security in the cloud remains a top concern for federal IT leaders.
Federal CIO Steven VanRoekel has spoken extensively regarding the importance of government agencies improving security strategies and adopting cloud services to facilitate cost savings and productivity gains.
"We will use technology to improve government productivity and lower barriers to citizen and business interaction with the government, all while bolstering cybersecurity," VanRoekel said in a recent interview with Federal News Radio.
While recent studies have revealed that security concerns are among the biggest obstacles to universal government and enterprise cloud adoption, organizations could consider implementing an advanced security solution built specifically to protect data in multiple virtual and cloud environments.
Cloud Computing News from SimplySecurity.com by Trend Micro
Spotlight
Cloud Computing
- Security in backups means more than just encryption
- Employees must buy into the company policy for better cloud security
- Desktop virtualization can enhance security performance
- Cybersecurity cooperation becoming military necessity
Virtualization
- Virtualization-specific challenges could threaten data security
- Evolving threats put security skills in high demand
- Virtualization security requires education, access control management
- Tips for launching effective virtual security tools
Internet Safety
- Virtualization-specific challenges could threaten data security
- Evolving threats put security skills in high demand
- Virtualization security requires education, access control management
- Tips for launching effective virtual security tools
Vulnerabilities & Exploits
CTO Insights
First Line of Defense
Newsletter
Stay up to date with the latest news and information on online threats.
Recent News
- FBI trying to train financial execs on cyber threats
- Wall Street has data security concerns over Bloomberg reporting
- Security in backups means more than just encryption
- Employees must buy into the company policy for better cloud security
Tag Cloud
cloud cloud computing cloud computing security Cloud Security Compliance & Regulations Consumerization Current News cybercrime Data Privacy data security Encryption Government Policy Internet Protection Internet Safety Internet Safety - DO NOT USE Internet Security Malware Mobile Security Mobility Policy Policy - DO NOT USE Privacy Privacy & Policy Private Cloud Public Cloud Reports Research Spotlight threat intelligence threat research Trend Labs Underground Economy virtualization Vulnerabilities Vulnerabilities - DO NOT USE web security web threats




Comments
No comments yet