Showing posts with label June 2010. Show all posts
Showing posts with label June 2010. Show all posts

Friday, June 25, 2010

The Federal Security Trifecta

I chose the term ‘Trifecta’ for today’s column because in horse racing, it designates three winners.  And I think that’s what we have here.
First, there’s the federal government, with ICAM, which stands for Identity, Credential and Access Management.  In a sense, it’s the other bookend to HSPD-12, which said “You must have a high quality credential.” And now ICAM comes along and says, “Here’s how you should use it.”
Second, there’s the cloud.  Or Software as a Service.  As we’ve discussed here before, it’s a new paradigm for procurement and delivery of software that says it’s smarter and more efficient for everyone concerned—both suppliers and users—to rent rather than own, consolidate rather than distribute, and by all means don’t pay for anything until you absolutely have to—which is to say, as a subscription. 
Last but not least, physical security is a big winner in all of this because it’s moving from having no seat at the IT table, to having an essential role due its newfound connection to identity and privacy.  Physical security providers have been quick to adopt cloud technologies and leverage them for a variety of new offerings informally known as Security-as-a-Service.
If you’d like to hear more, watch the Webcast on our Federal Government page.  Just click on the “Federal Security Trifecta” link in the second paragraph.

Thursday, June 3, 2010

The State of Public Sector Cloud Computing

Federal CIO Summarizes Cloud Progress in New Publication

Released in conjunction with the May 20 Federal Cloud Summit sponsored by NIST at the Department of Commerce, Vivek Kundra’s “The State of Federal Cloud Computing” outlines several new federal initiatives that will provide a big boost for cloud service providers of all stripes.

The first is Standards Acceleration to Jumpstart Adoption of Cloud Computing (SAJACC), a standards development effort that will be chaired by NIST and shared with the public through a new portal. The purpose of establishing standards is to increase portability of applications and interchangeability of service providers so that customers don’t get locked in to one particular technology stack.

The second is the Federal Risk and Authorization Management Program (FedRAMP), a much-needed cloud-era update to the aging FISMA framework for ensuring information security of federal computing applications. This “in for a dime, in for a dollar” approach leverages an initial security audit of a cloud provider from one agency across multiple other agencies who may choose to use the service at a later time. This prevents duplication of both effort and cost, and provides much faster deployment times for subsequent uses of a given cloud application.

The document also reiterates several of what are by now familiar themes previously introduced in earlier federal policy statements:
  • energy reduction through data center consolidation is facilitated by cloud computing,
  • federal budget planning for 2011 must include “an alternatives analysis that includes cloud computing,”
  • cloud computing will help close the federal government’s technology gap.
The report also concludes with 30 case studies of federal, state, and local cloud projects—a useful compendium of implementation advice, economic benefit, and deployment success.

- Steve Van Till