Risk
1/10/2012
02:46 PM
50%
50%

Feds Refine Cloud Security Standards

Federal CIO Council releases controls for new agency-wide program that standardizes security requirements for cloud-computing products and services.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters
The federal CIO Council has released security controls for the new agency-wide program that standardizes security requirements for cloud-computing products and services, a key move in setting standards for cloud security across the federal government.

More than 150 security controls in 16 categories have now been defined for the Federal Risk Assessment Program (FedRAMP), which provides common security requirements for cloud implementation on specific types of systems.

FedRAMP also provides ongoing risk assessments and continuous monitoring, and carries out government-wide security authorizations for vendors providing cloud services and infrastructure that will be posted on a public website.

[ Get more background on FedRAMP's goals. See Feds Aim To Speed Cloud Adoption With New Roadmap. ]

The release of these controls "is the critical first step that to successfully launching FedRAMP," as they are the basis for the program's standardized approach to the security authorization process for cloud products and services, according to a blog post on CIO.gov, the website for the CIO Council.

The FedRAMP Joint Authorization Board (JAB) went through an "extensive vetting process" to approve the controls since the initial release of FedRAMP documentation last year, according to the post. Indeed, FedRAMP has been in the planning stages for about two years but only was formally unveiled by U.S. CIO Steven Van Roekel in December.

The JAB also used feedback from those in both industry and government to create the controls so they "properly address the unique elements of authorizing cloud products and services, including multi-tenancy, control of an infrastructure, and shared resource pooling," according to the post.

To receive authorization from the federal government, agencies must implement the controls within a cloud service provider environment.

The categories cover comprehensive areas of security concern for IT systems. They are: access control; awareness and training; audit and accountability; assessment and authorization; configuration management; contingency planning, identification and authentication; incident response; maintenance; media protection; physical and environmental protection; planning; personnel safety; risk assessment; system and services acquisition; system and communications protection; and system and information integrity.

Each control covers a very specific area in a category that agencies must define for cloud-computing implementations. For example, controls under Access Control include account management, access enforcement, information flow enforcement, and separation of duties. Some of the requirements under personnel safety include individual controls for personnel screening, termination, and transfer, while controls under the incident response category include specific ones for incident response training, handling, monitoring, and reporting.

The systems and communications protection category--which covers many of the standard security procedures for system, such as public key infrastructure certificates, denial of service protection and use of cryptography--has the most controls, a total of 32. The awareness and training category has only four.

FedRAMP is a multiagency effort, with the Department of Homeland Security (DHS), the National Institute for Standards and Technology (NIST), and the General Services Administration (GSA) all playing key roles.

In fact, the new security controls are in line with NIST Special Publication 800-53, Revision 3, which provides recommended security controls for federal IT systems and organizations for low and moderate impact systems, according to the CIO.gov blog post.

InformationWeek is conducting our third annual State of Enterprise Storage survey on data management technologies and strategies. Upon completion, you will be eligible to enter a drawing to receive an Apple 32-GB iPod Touch. Take our Enterprise Storage Survey now. Survey ends Jan. 13.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-6093
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-6196
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSp...

CVE-2014-7247
Published: 2014-11-25
Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro Pro 2; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen; and Ichitaro 2014 Tetsu allows remote attackers to execute arbitrary code via a crafted file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?