Risk
1/10/2012
02:46 PM
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Feds Refine Cloud Security Standards

Federal CIO Council releases controls for new agency-wide program that standardizes security requirements for cloud-computing products and services.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters
The federal CIO Council has released security controls for the new agency-wide program that standardizes security requirements for cloud-computing products and services, a key move in setting standards for cloud security across the federal government.

More than 150 security controls in 16 categories have now been defined for the Federal Risk Assessment Program (FedRAMP), which provides common security requirements for cloud implementation on specific types of systems.

FedRAMP also provides ongoing risk assessments and continuous monitoring, and carries out government-wide security authorizations for vendors providing cloud services and infrastructure that will be posted on a public website.

[ Get more background on FedRAMP's goals. See Feds Aim To Speed Cloud Adoption With New Roadmap. ]

The release of these controls "is the critical first step that to successfully launching FedRAMP," as they are the basis for the program's standardized approach to the security authorization process for cloud products and services, according to a blog post on CIO.gov, the website for the CIO Council.

The FedRAMP Joint Authorization Board (JAB) went through an "extensive vetting process" to approve the controls since the initial release of FedRAMP documentation last year, according to the post. Indeed, FedRAMP has been in the planning stages for about two years but only was formally unveiled by U.S. CIO Steven Van Roekel in December.

The JAB also used feedback from those in both industry and government to create the controls so they "properly address the unique elements of authorizing cloud products and services, including multi-tenancy, control of an infrastructure, and shared resource pooling," according to the post.

To receive authorization from the federal government, agencies must implement the controls within a cloud service provider environment.

The categories cover comprehensive areas of security concern for IT systems. They are: access control; awareness and training; audit and accountability; assessment and authorization; configuration management; contingency planning, identification and authentication; incident response; maintenance; media protection; physical and environmental protection; planning; personnel safety; risk assessment; system and services acquisition; system and communications protection; and system and information integrity.

Each control covers a very specific area in a category that agencies must define for cloud-computing implementations. For example, controls under Access Control include account management, access enforcement, information flow enforcement, and separation of duties. Some of the requirements under personnel safety include individual controls for personnel screening, termination, and transfer, while controls under the incident response category include specific ones for incident response training, handling, monitoring, and reporting.

The systems and communications protection category--which covers many of the standard security procedures for system, such as public key infrastructure certificates, denial of service protection and use of cryptography--has the most controls, a total of 32. The awareness and training category has only four.

FedRAMP is a multiagency effort, with the Department of Homeland Security (DHS), the National Institute for Standards and Technology (NIST), and the General Services Administration (GSA) all playing key roles.

In fact, the new security controls are in line with NIST Special Publication 800-53, Revision 3, which provides recommended security controls for federal IT systems and organizations for low and moderate impact systems, according to the CIO.gov blog post.

InformationWeek is conducting our third annual State of Enterprise Storage survey on data management technologies and strategies. Upon completion, you will be eligible to enter a drawing to receive an Apple 32-GB iPod Touch. Take our Enterprise Storage Survey now. Survey ends Jan. 13.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Latest Comment: LOL.
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-3154
Published: 2014-04-17
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file conte...

CVE-2013-2143
Published: 2014-04-17
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

CVE-2014-0036
Published: 2014-04-17
The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled, which allows remote attackers to conduct man-in-the-middle attacks via unspecified vectors.

CVE-2014-0054
Published: 2014-04-17
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External ...

CVE-2014-0071
Published: 2014-04-17
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.

Best of the Web