Security-minded program could aid cloud transition

If approved, FedRAMP would develop a common core of security requirements for cloud services.

An interagency working group has developed a program to help agencies assess and manage the risks associated with moving applications to a cloud computing environment.

The Federal Risk and Authorization Management Program, developed by the Cloud Computing Advisory Council, will create governmentwide security requirements for cloud services based on the latest guidance from the National Institute of Standards and Technology. FedRAMP also will provide a common certification and accreditation process for security systems.

In an interview with GovInfoSecurity.com, the vice chairman of the council, NIST’s Peter Mell, said the organization has sent the details of the program to agencies, and after they give their blessing, the program will move into the testing phase.

Currently, it’s up to each agency to make sure that its cloud-based applications and systems are secure enough to store and manage government data.

“That leads to longer-than-necessary lead times to adoption and decisions not to adopt because the certification and accreditation process can be tedious,” writes J. Nicholas Hoover at InformationWeek.

A centralized process also should make it easier for industry vendors to develop products by providing them with a common set of requirements to meet, Hoover said.