The US Government agencies are subject to a wide variety of computing standards designed to protect sensitive government information.
The US Federal government has three program that are of specific interet to cloud security professionals:
The Common Criteria for Information Technology Security Evaluation (referred to as Common Criteria or CC) is an international standard (ISO/IEC 15408) for computer security certification.
Source: Common Criteria
The Common Criteria describes an approach for certifying a technology solution or product by evaluating it against the mandatory security requirements, assigning it an assurance level, and approving the solution’s or product’s operations. Government agencies extensively uses Common Criteria program in evaluating the hardware and software products.
The Federal Risk and Authorization Management Program (FedRAMP®) provides a standardized approach to security authorizations for Cloud Service Offerings.
Source: FedRAMP
As a government-wide program, the FedRAMP provides a standardized approach to security and risk assessment for cloud technologies to encourage adoption of secure cloud services throughout the federal government. In accordance with FISMA, OMB Circular A-130, and FedRAMP policies, the FedRAMP centralizes security requirements for the approval and ongoing cybersecurity of the cloud-based services.
FedRAMP provides as one-stop certification process for the security of cloud services. allowing vendors to go to a single source for certification that then applies across the US government.
The Federal Information Processing Standard Publication 140-2 (FIPS PUB 140-2) is a U.S. government computer security standard used to approve cryptographic modules.
Source: FIPS 140-2
This Federal Information Processing Standard (140-2) specifies the security requirements to approve cryptographic modules (implementations) for the use of government applications. All goverment agencies and their service providers must make sure all the computer based applications should comply with FIPS 140-2.
EA Capability Leader spearheads the work performed to develop an EA Capability within an organization.
Organizations operating in highly secure environments, such as the governments, military or defense industry, rely…
Weighted Shortest Job First (WSJF) is a prioritization model used to sequence work for maximum…
Do not waste your time with explanations. People only hear what they want to hear.…
Who Is A Stakeholder? A party that has an interest in an enterprise or project.…
Project Management discipline is the process & activity of planning, organizing and controlling resources, procedures…
This website uses cookies.