Risk
1/10/2012
02:46 PM
50%
50%

Feds Refine Cloud Security Standards

Federal CIO Council releases controls for new agency-wide program that standardizes security requirements for cloud-computing products and services.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters
The federal CIO Council has released security controls for the new agency-wide program that standardizes security requirements for cloud-computing products and services, a key move in setting standards for cloud security across the federal government.

More than 150 security controls in 16 categories have now been defined for the Federal Risk Assessment Program (FedRAMP), which provides common security requirements for cloud implementation on specific types of systems.

FedRAMP also provides ongoing risk assessments and continuous monitoring, and carries out government-wide security authorizations for vendors providing cloud services and infrastructure that will be posted on a public website.

[ Get more background on FedRAMP's goals. See Feds Aim To Speed Cloud Adoption With New Roadmap. ]

The release of these controls "is the critical first step that to successfully launching FedRAMP," as they are the basis for the program's standardized approach to the security authorization process for cloud products and services, according to a blog post on CIO.gov, the website for the CIO Council.

The FedRAMP Joint Authorization Board (JAB) went through an "extensive vetting process" to approve the controls since the initial release of FedRAMP documentation last year, according to the post. Indeed, FedRAMP has been in the planning stages for about two years but only was formally unveiled by U.S. CIO Steven Van Roekel in December.

The JAB also used feedback from those in both industry and government to create the controls so they "properly address the unique elements of authorizing cloud products and services, including multi-tenancy, control of an infrastructure, and shared resource pooling," according to the post.

To receive authorization from the federal government, agencies must implement the controls within a cloud service provider environment.

The categories cover comprehensive areas of security concern for IT systems. They are: access control; awareness and training; audit and accountability; assessment and authorization; configuration management; contingency planning, identification and authentication; incident response; maintenance; media protection; physical and environmental protection; planning; personnel safety; risk assessment; system and services acquisition; system and communications protection; and system and information integrity.

Each control covers a very specific area in a category that agencies must define for cloud-computing implementations. For example, controls under Access Control include account management, access enforcement, information flow enforcement, and separation of duties. Some of the requirements under personnel safety include individual controls for personnel screening, termination, and transfer, while controls under the incident response category include specific ones for incident response training, handling, monitoring, and reporting.

The systems and communications protection category--which covers many of the standard security procedures for system, such as public key infrastructure certificates, denial of service protection and use of cryptography--has the most controls, a total of 32. The awareness and training category has only four.

FedRAMP is a multiagency effort, with the Department of Homeland Security (DHS), the National Institute for Standards and Technology (NIST), and the General Services Administration (GSA) all playing key roles.

In fact, the new security controls are in line with NIST Special Publication 800-53, Revision 3, which provides recommended security controls for federal IT systems and organizations for low and moderate impact systems, according to the CIO.gov blog post.

InformationWeek is conducting our third annual State of Enterprise Storage survey on data management technologies and strategies. Upon completion, you will be eligible to enter a drawing to receive an Apple 32-GB iPod Touch. Take our Enterprise Storage Survey now. Survey ends Jan. 13.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.