This post was originally published on Cloud Computing Journal.
When describing cloud computing, terms like highly scalable, efficient, and on-demand probably come to mind. Unfortunately, those same descriptors aren’t commonly associated with operations in the federal government.
In 2010, the White House’s Office of Management and Budget set out to change that with the Cloud First Policy. Through cloud computing, the OMB aimed to help federal agencies consolidate and provide new services cheaper and faster.
But with cloud adoption comes the heightened challenge of ensuring a secure and trustworthy environment. That’s where FedRAMP comes in.
FedRAMP defines the requirements for cloud service providers’ security controls, including vulnerability scanning, incident monitoring, logging, and reporting. CSPs in use at federal agencies or in acquisition must meet the cloud computing requirements defined by FedRAMP.
Whether or not your company currently works with government agencies, there are several benefits to preparing for FedRAMP:
If you have no plans to pursue government contracts, don’t blindly spend money on certification just to check a compliance box. FedRAMP aims to centralize compliance checking in a “do once, use many” process, but the costs can be quite high. In any case, simply evaluating your organization against FedRAMP’s standards will provide an invaluable risk assessment.
However, CSPs that could potentially be a part of the government ecosystem – either directly or indirectly through their customers – should prepare themselves for FedRAMP. They need to weigh the costs and benefits of determining where their organizations align with the federal government’s Cloud First policy.
Delegate the Details
FedRAMP compliance is a highly detailed process, and the planning itself is exhaustive. You’ll need to seek outside help to create your system security plan and work with a third-party assessment organization.
Before you bring in outsiders, however, there are a few preparations you need to make internally. The FedRAMP PMO has created extensive checklists to help you do as much as possible on your own.
Once you’ve gone through the checklists, find a partner to help you do the following:
Getting your FedRAMP certification is a lengthy process, and it’s not the right option for every company. By taking the necessary steps and preparing yourself in advance, you’ll be one step closer to enjoying the competitive advantage it affords.