+1 609-PRO-GURU
office@TheProjectManagement.Guru
0
Free Consultation
TheProjectManagement.GuruTheProjectManagement.Guru
  • Home
  • About Us
  • Services
  • Blog
  • Contact
Back
  • Home
  • About Us
  • Services
  • Blog
  • Contact
  • Home
  • Blog
  • Cybersecurity
  • Government Cloud Standards

Cybersecurity

22 Feb

Government Cloud Standards

  • By Kotesh Kommanaboyina
Government Cloud Standards - A Comprehensive Overview

The US Government agencies are subject to a wide variety of computing standards designed to protect sensitive government information.

Government Cloud Standards: A Comprehensive Guide

The US Federal government has three program that are of specific interet to cloud security professionals:

  • Common Criteria
  • FedRAMP (The Federal Risk and Authorization Management Program)
  • FIPS 140-2

Common Criteria

The Common Criteria for Information Technology Security Evaluation (referred to as Common Criteria or CC) is an international standard (ISO/IEC 15408) for computer security certification.

Source: Common Criteria

The Common Criteria describes an approach for certifying a technology solution or product by evaluating it against the mandatory security requirements, assigning it an assurance level, and approving the solution’s or product’s operations. Government agencies extensively uses Common Criteria program in evaluating the hardware and software products.

FedRAMP

The Federal Risk and Authorization Management Program (FedRAMP®) provides a standardized approach to security authorizations for Cloud Service Offerings.

Source: FedRAMP

As a government-wide program, the FedRAMP provides a standardized approach to security and risk assessment for cloud technologies to encourage adoption of secure cloud services throughout the federal government. In accordance with FISMA, OMB Circular A-130, and FedRAMP policies, the FedRAMP centralizes security requirements for the approval and ongoing cybersecurity of the cloud-based services.

  • FISMA: Federal Information Security Modernization Act (FISMA) enforces agencies to protect federal information
  • OMB Circular A-130: Office of Management and Budget (OMB) states that when agencies implement FISMA, they must comply to National Institute of Standards and Technology (NIST) standards and guidelines
  • FedRAMP Policy: FedRAMP leverages National Institute of Standards and Technology (NIST) standards and guidelines to provide standardized security requirements for cloud services; a conformity assessment program; standardized authorization packages and contract language; and a repository for authorization packages

FedRAMP provides as one-stop certification process for the security of cloud services. allowing vendors to go to a single source for certification that then applies across the US government.

FIPS 140-2

The Federal Information Processing Standard Publication 140-2 (FIPS PUB 140-2) is a U.S. government computer security standard used to approve cryptographic modules.

Source: FIPS 140-2

This Federal Information Processing Standard (140-2) specifies the security requirements to approve cryptographic modules (implementations) for the use of government applications. All goverment agencies and their service providers must make sure all the computer based applications should comply with FIPS 140-2.

Tags:Cloudcloud securityCloud StandardsCybersecurityCybersecurity PoliciesFISMAGovernment Cloud Standardsgovernment data protectionUS Federal Govt
Avatar of Kotesh Kommanaboyina
Kotesh Kommanaboyina
MBA | PMP | PgMP | TOGAF® 9 Certified | SPC6

Share

Categories

  • Agile Project Management
  • Cybersecurity
  • Enterprise Architecture
  • Project Management
  • Scaled Agile Framework
  • TOGAF

Tags

Agile Project Management Cloud cloud security Cloud Standards Computation Models Confidential Computing cost of delay Cybersecurity Cyber Security Cybersecurity Policies EA Capability economic benefit effective project meetings Emerging Technologies FISMA global economic shifts Government Cloud Standards government data protection importance of meetings job duration leadership leadership styles Management Discipline memory encryption PMI prioritization program stakeholder engagement progress monitoring Project Management Project Management Discipline project management principles Project Manager rapidly changing world risk management SAFe Scaled Agile Framework stakeholder analysis stakeholder communication stakeholder management tips for project meetings TOGAF trusted execution environments US Federal Govt Weighted Shortest Job First WSJF
TheProjectManagement.Guru Logo

We help clients create long-term value for all stakeholders. Empowered by SMEs and experienced consultants, our services and solutions provide trust through assurance and help clients transform, grow and operate.

Dont miss out on new posts


    Don’t worry, we won’t spam you!

    © 2015 - 2023 TheProjectManagement.Guru | All rights reserved.

    Want to become a Coach/Mentor/Blogger?

    Join your hand with us for a better career and bright future. We can together conquer the world!

    write us now

    ×