Compliance Cloud computing issues
u.s. federal agencies have been directed office of management , budget use process called fedramp (federal risk , authorization management program) assess , authorize cloud products , services. federal cio steven vanroekel issued memorandum federal agency chief information officers on december 8, 2011 defining how federal agencies should use fedramp. fedramp consists of subset of nist special publication 800-53 security controls selected provide protection in cloud environments. subset has been defined fips 199 low categorization , fips 199 moderate categorization. fedramp program has established joint accreditation board (jab) consisting of chief information officers dod, dhs, , gsa. jab responsible establishing accreditation standards 3rd party organizations perform assessments of cloud solutions. jab reviews authorization packages, , may grant provisional authorization (to operate). federal agency consuming service still has final responsibility final authority operate.
Comments
Post a Comment