Two Amazon Web Services environments attain FedRAMP compliance

Last week, Amazon announced that it had received separate agency authorizations to operate (ATO) from the U.S. Department of Health and Human Services (HHS) for two of its Amazon Web Services cloud computing offerings, and that…

VA decision to allow iPad use without FIPS certification provides good example of risk-based decsion making

The decision by Department of Veterans Affairs CIO Roger Baker to allow users to connect mobile devices such as the Apple iPad and iPhone to the agency’s computing network provides a good example of the trade-off…

Six weeks away from Cyberscope deadline, many agencies remain unclear on requirements

Nearly a year ago, the federal government announced its new Cyberscope online application for reporting agency information associated with the Federal Information Security Management Act (FISMA). In more detailed subsequent guidance issued in April through Memorandum…

Google Apps for Government receives federal authorization to operate from GSA

Google announced today that its public-sector focused cloud computing service, Google Apps for Government, successfully completed a security certification and accreditation (C&A) process and received an authorization to operate (ATO) from the General Services Administration. This…

Agencies receive new guidance, privacy requirements on use of third-party websites

The Office of Management and Budget (OMB) today released a new memo to all heads of executive departments and agencies, “Guidance for Agency Use of Third-Party Websites and Applications,” that lays out a set of general…

Government first-movers looking to get a jump on continuous monitoring

With new federal agency FISMA reporting requirements taking effect in November, several agencies are taking steps now to get ahead of the requirements and anticipate some additional security metrics likely to be added in the near…

NIST answers to questions on continuous monitoring suggest no drastic change in approach

In the wake of the release of its updated Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems, which among other things calls for federal agencies to continuously monitor the security…