From: Pillsbury
FedRAMP Accelerates the Process for Federal Contractors to Obtain Cloud Service Provider Authorizations and DoD Revises its Cloud Computing Security Requirements Guide for FedRAMP+
Authors: C. Joël Van Over, Brian P. Cruz, Selena Brady
***
As a threshold requirement, a cloud service provider (CSP) must successfully navigate the Federal Risk and Authorization Management Program (FedRAMP) before it is authorized to provide a cloud service offering to the Federal government. The new FedRAMP Accelerated program, launched in March 2016, is intended to provide a faster, cost-effective, risk-based approach for authorizing CSP to provide cloud services to government agencies. FedRAMP is mandatory for low and moderate risk levels for all cloud deployments and associated service models. FedRAMP is currently developing a higher risk level authorization and has issued higher level certifications in a pilot program. CSPs that have not been certified by FedRAMP previously and either wish to provide cloud services to the federal government, or use cloud services in performing federal contracts, should consider the new FedRAMP Accelerated process to achieve the authority to operate in compliance with FedRAMP security control standards. This Advisory reviews the new FedRAMP Accelerated process, and provides background on FedRAMP for those considering the benefits of navigating the FedRAMP process. The General Services Administration (GSA) anticipates that the new accelerated process will reduce the time it takes to earn FedRAMP authorization by 75%, making it possible to achieve authorization in as little as three months.1
Also in March 2016, the Department of Defense (DoD) updated its Cloud Computing Security Requirements Guide (SRG), a significant document that establishes DoD’s baseline security for cloud computing, effectively establishing FedRAMP+ requirements for DoD CSPs. Between March and June 8, 2016, DoD (through the Defense Information Systems Agency (DISA) has issued over 20 related Security Technical Implementation Guides (STIGS) that apply to specific technologies, products, and applications. The SRG requires compliance with all STIGs applicable to relevant systems.2 According to DISA, “the STIGS contain technical guidance to ‘lock down’ information systems/software that might otherwise be vulnerable to a malicious attack.”3 The SRG covers both internal DoD systems and external (commercial) CSPs and their cloud service offerings through the secret level security classification. DoD contractors are required to comply with the SRG under DoD’s recently adopted cloud services regulations and implementing contract clauses.4 The SRG describes how the FedRAMP process relates to SRG compliance and how it differs.
Leave a Reply