This article is an excerpt from GovLoop’s recent guide, “Your Guide to Cloud Security in Government Today: Making the Most of FedRAMP.” Download the full guide here.
There was a time when most agencies shied away from putting their data in the cloud. Skeptics questioned whether cloud-based systems could meet government requirements and how they could verify those claims, especially if they couldn’t see or touch physical hardware.
But efforts such as FedRAMP have helped to ease those concerns by providing baseline requirements for securing cloud products and services in a standard way. Using FedRAMP as a guide, agencies still must determine which cloud systems best support their mission. GovLoop and AWS partnered to highlight what secure cloud vendors like AWS have to offer agencies that want to take a thoughtful, mission-focused approach to cloud adoption.
For agencies, security classification has been one of the biggest barriers in moving to the cloud.
Security requirements for data, applications and workloads greatly dictate where those things may reside and run. In June 2016, AWS became the first cloud service provider to receive authorization to support FedRAMP High workloads. The “High” designation means that any loss of confidentiality, integrity or availability of the data in that system could be expected to have a severe or catastrophic effect on organizational operations, assets or individuals.
The creation of FedRAMP requirements to secure high-impact systems was a major milestone not only for cloud service providers like AWS but also for government agencies. The reason? Federal agencies wanted to take advantage of the benefits of secure commercial cloud — even for mission-critical systems. They wanted the ability to quickly adapt to varying workloads and to only pay for the IT services they use.
Offerings like AWS GovCloud (US) provide agencies compliance without compromise by delivering a secure environment to run sensitive government workloads. Currently, agencies are using AWS GovCloud to power various innovative projects, including analyzing data on social media to collect information on adverse drug effects and collecting images from Mars.
As agencies move more workloads into the cloud, investing in offerings that further their mission in a secure, cost-effective way is key.