Presentation is loading. Please wait.

Presentation is loading. Please wait.

Assessment and Authorization for Cloud Computing Dr. Sarbari Gupta 703-437-9451 ext 12 Third Workshop on Cyber Security & Global.

Similar presentations


Presentation on theme: "Assessment and Authorization for Cloud Computing Dr. Sarbari Gupta 703-437-9451 ext 12 Third Workshop on Cyber Security & Global."— Presentation transcript:

1 Assessment and Authorization for Cloud Computing Dr. Sarbari Gupta sarbari@electrosoft-inc.com 703-437-9451 ext 12 Third Workshop on Cyber Security & Global Affairs May 31 – June 2, 2011

2 Page 2 Overview  US Mandates and Programs affecting Cloud Computing  Government-wide Risk and Authorization of Cloud Computing  Challenges faced with Cloud Computing Assessment and Authorization

3 Page 3 US Mandates and Programs  FISMA – Federal Information Security Management Act or 2002  Defines a compliance framework for securing government systems  NIST responsible for standards & guidelines  FedRAMP – Federal Risk Management and Authorization Program  Designed to solve the security authorization problems highlighted by cloud computing  “authorize once, use many”

4 Page 4 Challenges with FISMA Measures security planning and not information security Interpretation of FISMA requirements and NIST guidelines varies greatly Same system is not compatible across agencies Continuous Monitoring Inadequate

5 Page 5 GSA IaaS Cloud Computing Environment  Cloud Storage Services  Storage for Files, Data and Data Objects  Well-defined Storage & Bandwidth Tiers  Virtual Machines  CPU (RAM, Disk space, Data transfer Bandwidth)  Operating System  Persistence  Cloud Web Hosting  CPU, OS, Software

6 Page 6 GSA IaaS – Separation of Duties

7 Page 7 FISMA / FedRAMP Details

8 Page 8 FISMA / FedRAMP Details

9 Page 9 Control Tailoring Workbook Fill this column out if the system setting is different than the GSA defined setting in the previous column

10 Page 10 FISMA / FedRAMP Details

11 Page 11 FISMA / FedRAMP Details

12 Page 12 FedRAMP Challenges  Continuous monitoring not adequate  SLA’s not validated in real-time  Manual processes prone to error  Security Control testing may be done too far apart  Security Management not adequate  Data collection for analysis inadequate  Corrective action hard to negotiate Can outsource responsibility but not accountability

13 Page 13 End-user Visibility is Key

14 Page 14 A&A Process for Cloud Computing Questions? sarbari@electrosoft-inc.com


Download ppt "Assessment and Authorization for Cloud Computing Dr. Sarbari Gupta 703-437-9451 ext 12 Third Workshop on Cyber Security & Global."

Similar presentations


Ads by Google