Program to vet cloud service vendors to launch June 6

From: Federal Times

By NICOLE BLAKE JOHNSON

A program intended to standardize the government’s security certification of cloud products and services is expected to launch June 6 with the help of nine organizations named last week.

As part of the Federal Risk and Authorization program (FedRAMP), cloud vendors must first hire these approved third-party assessment organizations, or 3PAOs, to review and validate that they’ve implemented minimum security standards.

Companies already providing cloud technology to agencies under the General Services Administration’s Infrastructure-as-a-Service contract will be among the first to undergo an additional review and approval process by an interagency board of chief information officers. But agency CIOs will ultimately decide which products and services they will use.

FedRAMP is meant to replace and lower the cost of the varied security assessments of information technology systems agencies now use.  According to 2009 data, the most recent available, agencies spend $300 million annually to test the security of IT systems and approve their use in the federal government.

“One of the promises and the benefits of FedRAMP is that we think it will save about 30 to 40 percent of governmentwide costs associated with assessing, authorizing, procuring and continuously monitoring these cloud solutions,” federal Chief Information Officer Steven VanRoekel said in December when announcing FedRAMP. The government spends “hundreds of millions of dollars a year securing information technology systems, and much of that work is duplicative, inconsistent and time-consuming.”

FedRAMP will allow agencies to reduce the number of people it takes to assess and authorize systems by 50 percent and cut the assessment time by 75 percent, according to the Office of Management and Budget.

“We are paid to think like hackers and to identify those issues that hackers could exploit,” said Paul Nguyen, vice president of cyber solutions at the Reston, Va.-based Knowledge Consulting Group. The company is one of the approved assessors and has a dedicated team of 30 people to verify the security of both commercial cloud and government information technology solutions.

FedRAMP is also intended to speed up widespread adoption of cloud products and services. However, the program’s success will rely on participation from chief information officers and chief information security officers, and their willingness to trust reviews conducted by others.

Richard Spires, Department of Homeland Security CIO, said it is important “to have credibility out of the gate.” It does the government no good if security officers and other officials don’t approve the quality of FedRAMP’s security reviews, he said.

“It is a very strong foundation,” Teri Takai, CIO at the Defense Department, said of FedRAMP. “Some of the challenges that I think we’re going to have internally are actually getting all the CIOs and all those who buy services to acknowledge that the FedRAMP certification is a valid certification for them to use and that they don’t have to recertify you,” Takai told vendors this month at a TechAmerica event.

Takai said DoD’s upcoming cloud strategy is based on the assumption that FedRAMP will ensure cloud products and services meet baseline security requirements set by the National Institute of Standards and Technology. DoD will, however, have some additional security requirements, she said.

Both Spires and Takai serve on the board of CIOs charged with overseeing aspects of FedRAMP. The board will define and update the security requirements for vendors’ cloud computing products, and decide when vendors’ security packages will be reviewed by the board.

The General Services Administration has completed at least two test runs of the FedRAMP process to work out any kinks before the June launch.

The agency held training sessions for CIOs from GSA, DoD and DHS to simulate their roles on the interagency review board, said Dave McClure, associate administrator of GSA’s Office of Citizen Services and Innovative Technologies. CIOs reviewed mock security assessments to discuss if they met FedRAMP standards.

Anywhere from six to 20 contractors will go through FedRAMP in the first six to eight months, McClure said.

“We are trying to get the process worked out and tested,” he said. “How do we set this up so that we streamline [FedRAMP] and … become aggressive solution finders for answers to questions or problems?”

The interagency group of CIOs, called the joint authorization board, will have to meet virtually and in person to work through the reviews, McClure said. The board will rely heavily on technical representatives to help review vendors’ security packets and streamline the review process.

GSA has not decided how the government will determine the ongoing security of its vendors. What information will be exchanged and who can access the information has not yet been determined, McClure said. GSA’s FedRAMP office is working through the logistics.

CIOs expect FedRAMP will lead to increased competition for federal business as more agencies look to adopt secure cloud services, Spires said.

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *