Federal tech outlook: Cloudy with a chance of information assurance

Analysis
Jun 27, 20124 mins

Two new initiatives may help the federal government warm up to the cloud and information assurance.

Soft and Light Fluffy White Feather Floating in The Sky with Clouds. Abstract Feather Heavenly Dreamy Fluffy Colorful Sky.
Credit: Siwakorn1933 / Shutterstock

The federal government, information security (or information assurance [IA] in federal parlance), and the cloud have always been uncomfortable bedfellows, but two new initiatives may mean public sector information security professionals will sleep a little more soundly in future.

First up is the FedRAMP (Federal Risk and Authorization Management Program) initiative, a process to standardize the security requirements that cloud computing service providers must meet to be eligible to win contracts with government agencies. FedRAMP was recently launched to provide a benchmark for outsourced cloud computing projects. By adhering to a uniform framework for all cloud service models – Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS) – under a broad governance model that includes the United States Department of Defense (DoD), DHS, GSA and NIST, the hope is that FedRAMP will reduce the risks associated with placing sensitive information on third-party cloud environments.

RELATED: Don’t tread on me…or Google, either

The Legacy of Howard Schmidt: Take Care of the Basics and Information Security Will Take Care of Itself

According to David McClure, associate administrator of the General Services Administration’s Office of Citizen Services and Communication, who spoke last week at the 2012 Gartner Security & Risk Management Summit, FedRAMP has four main objectives:

  • Develop a set of baseline security controls;
  • Validate a set of trusted third-party assessment organizations (3PAOs);
  • Establish trust in the program using a Joint Authorization Board to ensure each agency’s cloud provider assessments meet FedRAMP standards; and
  • Facilitate the transition to continuous security monitoring for government cloud computing implementations.

The second initiative is an evolution of the DoD’s current information assurance certification and accreditation (C&A) model, known as DIACAP, to a new risk-based methodology called DIARMF (Defense Information Assurance Risk Management Framework). The migration of the DoD to DIARMF will mean that, for the first time, all federal agencies across DoD, intelligence and civilian branches will finally be unified on a single, consistent set of security controls and the same risk management framework all of which are developed by NIST – the agency that should be responsible for federal security standards. This is no small feat; for many years, the DoD was standardized on DIACAP (and its predecessor, DITSCAP), both based on the DoD’s 8500.2 security controls standard. The intelligence community utilized DCID 6/3 (and other standards), and civilian agencies utilized the NIST 800-53 controls and NIST FIPS standards, as mandated by FISMA. This fragmented approach to security controls has resulted in a nightmare for getting data across inter-agency barriers, and resulted in inconsistent application of security controls – as well as difficult audits – across the federal sector for years.

As this comparison of DIACAP and DIARMF from the Infosec Institute shows, a series of unified standards are now going to be applied across the entire spectrum of federal agencies. What is perhaps most important about the migration to DIARMF is the focus on continuous assessment of security controls: whereas DIACAP was more of a “checkbox” approach to IA, DIARMF will be heavily focused on continuous monitoring – and as a result, DIARMF seeks to not just be a C&A standard that measures controls, but also provides actual security. According to the latest Verizon Data Breach Investigative Report, the application of basic or intermediate could have stopped 97% of data breaches in 2011, so we’re confident that that these initiatives will have a significant impact on the safety of information on federal networks.

We’ve long said that the days of any value from “checkbox-based” assessments and compliance activities are long over, and it’s great to see that federal agencies now have formal systems and processes to help them to deliver it. Continuous monitoring of an information security posture against a benchmarked position – in other words, knowing “what is normal” – is the only way that both federal and commercial information security professionals can effectively protect against advanced persistent threats.