FedRAMP: Keeping up with changing cloud security standards

From: FCW

What executives need to know about the government-wide standards that become mandatory in June

By Michael Hardy

Just as agencies and vendors are starting to get the knack of complying with the Federal Risk and Authorization Management Program, the General Services Administration is preparing to revise FedRAMP’s baseline standards.

GSA solicited public comments last summer on the FedRAMP update and is now revising the standards, which cloud service providers must meet in order to sell to agencies. The changes are based on the revised National Institute of Standards and Technology Special Publication 800-53 released in April 2013. It outlines updated security and privacy controls for federal information systems.

The update to FedRAMP’s baseline standards will ensure that the security controls stay relevant as cloud computing evolves, a GSA spokesman said.

The CIOs at GSA, the Defense Department and the Department of Homeland Security, who lead the FedRAMP Joint Authorization Board, have already reviewed the revised baseline. GSA is now waiting for NIST to complete test cases — likely by March — before moving forward with the transition.

Agencies have until June to ensure that all the cloud service providers they use (or with whom they are in contract negotiations) are FedRAMP-approved. The Office of Management and Budget’s PortfolioStat program is providing insight into the progress agencies are making toward that goal, the GSA spokesman said.

 

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *