Cloud Computing Best Practices. Creating Effective Cloud Computing Contracts for the Federal Government: Best Practices for Acquiring IT as a Service



Similar documents
Allison Stanton, Director of E-Discovery U.S. Department of Justice, Civil Division. U.S. Department of Agriculture

Allison Stanton Director of E-Discovery U.S. Department of Justice, Civil Division

Seeing Though the Clouds

Audit of the CFPB s Acquisition and Contract Management of Select Cloud Computing Services

Creating Effective Cloud Computing Contracts for the Federal Government

Overview. FedRAMP CONOPS

Federal Cloud Computing Initiative Overview

December 8, Security Authorization of Information Systems in Cloud Computing Environments

Written Testimony. Mark Kneidinger. Director, Federal Network Resilience. Office of Cybersecurity and Communications

Management of Cloud Computing Contracts and Environment

How To Use Cloud Computing For Federal Agencies

Concurrent Technologies Corporation (CTC) is an independent, nonprofit, applied scientific research and development professional services

Clouds on the Horizon Cloud Security in Today s DoD Environment. Bill Musson Security Analyst

The Cloud Seen from the U.S.A.

Cloud Security. A Sales Guy Talks About DoD s Cautious Journey to the Public Cloud. Sean Curry Sales Executive, Aquilent

The Council of the Inspectors General on Integrity and Efficiency s Cloud Computing Initiative

Federal Risk and Authorization Management Program (FedRAMP)

CLOUD COMPUTING. Agencies Need to Incorporate Key Practices to Ensure Effective Performance

Cloud Security for Federal Agencies

Status of Cloud Computing Environments within OPM (Report No. 4A-CI )

Cloud Computing. Report No. OIG-AMR UNITED STATES GOVERNMENT National Labor Relations Board Office of Inspector General.

Office of Inspector General Audit Report

ITL BULLETIN FOR JUNE 2012 CLOUD COMPUTING: A REVIEW OF FEATURES, BENEFITS, AND RISKS, AND RECOMMENDATIONS FOR SECURE, EFFICIENT IMPLEMENTATIONS

Cisco Cloud Assessments. Justin Tang

Purpose. Service Model SaaS (Applications) PaaS (APIs) IaaS (Virtualization) Use Case 1: Public Use Case 2: Use Case 3: Public.

Cloud Services The Path Forward. Mr. Stan Kaczmarczyk Acting Director - Strategic Solutions and Security Services FAS/ ITS, GSA

Managing Cloud Computing Risk

Security Issues in Cloud Computing

Kent State University s Cloud Strategy

Cloud Computing in the Federal Sector: What is it, what to worry about, and what to negotiate.

Report via OMB s Integrated Data Collection (IDC), 10

Federal Aviation Administration. efast. Cloud Computing Services. 25 October Federal Aviation Administration

Enterprise Managed Cloud Computing at NASA. Karen Petraska NASA Office of the CIO Computing Services Service Office (CSSO) October 1, 2014

How to Use the Federal Risk and Authorization Management Program (FedRAMP) for Cloud Computing

DEPARTMENT OF VETERANS AFFAIRS VA DIRECTIVE 6517 CLOUD COMPUTING SERVICES

GAO INFORMATION TECHNOLOGY REFORM. Progress Made but Future Cloud Computing Efforts Should be Better Planned

Cloud Computing and Records Management

Cloud Computing Contract Clauses

A Strawman Model. NIST Cloud Computing Reference Architecture and Taxonomy Working Group. January 3, 2011

STATEMENT OF. Dr. David McClure Associate Administrator Office of Citizen Services and Innovative Technologies General Services Administration

OWASP Chapter Meeting June Presented by: Brayton Rider, SecureState Chief Architect

How To Manage Cloud Computing In The United States Of American Agriculture

EPA Classification No.: CIO 2155-P-3.0 CIO Approval Date: 04/04/2014 CIO Transmittal No.: Review Date: 04/04/2017

CLOUD COMPUTING. A Primer

DEPARTMENT AGENCY STATEMENT OF OBJECTIVES FOR CLOUD MIGRATION SERVICES: INVENTORY, APPLICATION MAPPING, AND MIGRATION PLANNING MONTH YYYY TEMPLATE

TESTIMONY OF MR. RICHARD SPIRES CHIEF INFORMATION OFFICER U.S. DEPARTMENT OF HOMELAND SECURITY BEFORE THE COMMITTEE ON HOMELAND SECURITY

1. From the CIO Strategic Direction for Cloud Computing at Kent State Cloud Computing at Kent State University 5

STATEMENT OF SYLVIA BURNS CHIEF INFORMATION OFFICER U.S. DEPARTMENT OF THE INTERIOR BEFORE THE

Federal Data Center Consolidation Initiative

Securing and Auditing Cloud Computing. Jason Alexander Chief Information Security Officer

Cloud Computing A NIST Perspective & Beyond. Robert Bohn, PhD Advanced Network Technologies Division

The Keys to the Cloud: The Essentials of Cloud Contracting

OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT

The Hybrid Cloud: Bringing Cloud-Based IT Services to State Government

Perspectives on Moving to the Cloud Paradigm and the Need for Standards. Peter Mell, Tim Grance NIST, Information Technology Laboratory

Project Type Guide. Project Planning and Management (PPM) V2.0. Custom Development Version 1.1 January PPM Project Type Custom Development

Cloud Security Introduction and Overview

Cloud Computing. Course: Designing and Implementing Service Oriented Business Processes

Cloud Computing and Government Services August 2013 Serdar Yümlü SAMPAŞ Information & Communication Systems

Federal Cloud Security

A New Way to Compute or: How I Learned to Stop Worrying and Love the Cloud

A COALFIRE PERSPECTIVE. Moving to the Cloud. NCHELP Spring Convention Panel May 2012

Cloud Computing Best Practices and Considerations for Project Managers Mike Lamoureux, PMP, MBA. Page 1

Cloud Computing; What is it, How long has it been here, and Where is it going?

East African Information Conference th August, 2013, Kampala, Uganda. Security and Privacy: Can we trust the cloud?

ISSUE BRIEF. Cloud Security for Federal Agencies. Achieving greater efficiency and better security through federally certified cloud services

Security Authorization Process Guide

How To Cloud Compute At The Cloud At The Cyclone Center For Cnc

IBM Cloud Security Draft for Discussion September 12, IBM Corporation

NIST Cloud Computing Program

journey to a hybrid cloud

Cloud Computing. by Civic Consulting (research conducted October 2011 January 2012)

IT Security Risk Management Model for Cloud Computing: A Need for a New Escalation Approach.

Information Security Program CHARTER

The NIST Definition of Cloud Computing (Draft)

Why Migrate to the Cloud. ABSS Solutions, Inc. 2014

Expert Reference Series of White Papers. Understanding NIST s Cloud Computing Reference Architecture: Part II

ClOP CHAPTER Departmental Information Technology Governance Policy TABLE OF CONTENTS. Section 39.1

What Cloud computing means in real life

DoD ENTERPRISE CLOUD SERVICE BROKER CLOUD SECURITY MODEL

Federal CIO: Cloud Selection Toolkit. Georgetown University: Chris Radich Dana Christiansen Doyle Zhang India Donald

Cloud Computing in a Regulated Environment

New Computing Models, and What They Mean to the Small and Mid-Sized Business Consumer

CLOUD COMPUTING. Additional Opportunities and Savings Need to Be Pursued

LEGAL ISSUES IN CLOUD COMPUTING

DoD CIO s 10-Point Plan for IT Modernization. Ms. Teri Takai DoD CIO

NAVIGATING THE MAZE LEGAL CIO ROUNDTABLE RETREAT March 3-5, 2013 The Boulders Hotel Carefree, Arizona CIO Roundtable Retreat

Cloud Security Implications for Financial Institutions By Scott Galyk Director of Software Development FIMAC Solutions, LLC

{Moving to the cloud}

Cloud Computing Cluster Introduction to Cloud Computing. Rick Martin, Co-chair, Cloud Computing Cluster August 26, 2013

AUDIT REPORT. The Department of Energy's Management of Cloud Computing Activities

2.0 ROLES AND RESPONSIBILITIES

Identity & Access Management The Cloud Perspective. Andrea Themistou 08 October 2015

Overview of Cloud Computing and Cloud Computing s Use in Government Justin Heyman CGCIO, Information Technology Specialist, Township of Franklin

Cloud-Based ICT Services Checklist

Cloud Security: Evaluating Risks within IAAS/PAAS/SAAS

John Essner, CISO Office of Information Technology State of New Jersey

Cloud Computing are you ready?

Legal Issues in the Cloud: A Case Study. Jason Epstein

Transcription:

Cloud Computing Best Practices Cloud Computing Best Practices Creating Effective Cloud Computing Contracts for the Federal Government: Best Practices for Acquiring IT as a Service

Overview Cloud Computing What is it? Cloud First Policy and Guidance The Cloud Procurement White Paper Minimizing Litigation Risk and Cost Slide 2

What is Cloud Computing? NIST Definition Cloud computing is a model for enabling convenient, on demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model promotes availability and is composed of five essential characteristics, three service models, and four deployment models. Source: NIST, Definition of Cloud Computing, Draft version 15, http://csrc.nist.gov/groups/sns/cloud computing/index.html Laymen's Definition Cloud is essentially utility computing Automated services (no humans needed for change in services) Services are consumed as used ( pay per drink ) Enabled via the internet (accessible anywhere) Elasticity in amount of services consumed (rapid provisioning and deprovisioning) Transition from capital expenses to operating expense Slide 3

What Services Are In The Cloud? Software SaaS (software as a service) Applications available as an on demand service End user applications Platform PaaS (platform as a service) IT and developer tools for database and testing environments to develop applications Development or deployment activities Infrastructure IaaS (infrastructure as a service) Computing, Storage and Hosting Services Network administrators Source: http://info.apps.gov/node/17 Common Examples Applications, Internet Services Social Media (Blogs, Wikis) Email, E Meetings Productivity Tools (Office) Application Development (Workflow and Automation) Security Services (Single Sign On, Authentication) Database Management Directory Services Mainframes Servers Storage IT Facilities/Hosting Services Slide 4

What Types of Clouds Are There? PRIVATE CLOUD Operated solely for an organization COMMUNITY CLOUD Shared by several organizations can be public or private PUBLIC CLOUD Available to the general public HYBRID CLOUD Composition of two or more clouds (private, community, or public) Source: http://info.apps.gov/node/17 Slide 5

Cloud: A Fundamental Shift in IT Source: www.cio.gov Slide 6

Cloud: Cheaper, Better, Faster Cloud = Future State of Government IT A fundamental shift: Agencies get state of the art products and services when they need them, at lower, commodity based prices. Government can redirect scarce resources to mission critical efforts as opposed to managing IT. Cheaper Save money & help lower the cost of government operations while driving innovation by avoiding duplicative infrastructure by using pay as you go service models Better Allows key resources to focus on mission critical activities and/or use solutions and services on demand or as needed Faster Decrease time tomarket to deploy or implement IT solutions via secure, easy to use contract vehicles available to federal & state and local government Slide 7

Administration s Drive to the Cloud The Administration s Federal Cloud Computing Strategy requires agencies to default to cloud based solutions whenever a secure, reliable and cost effective cloud option exists however, the move to the cloud requires a dramatic shift in the way Federal agencies buy IT from capital expenditures to operating expenditures. With this shift comes a learning curve as the government analyzes how to best procure this new service based model.... Steven VanRoekel U.S. Chief Information Officer, OMB February 24, 2012 Slide 8

Federal Timeline for Cloud Cloud First 25 Point Plan to Reform Federal IT December 9, 2010 FedRAMP Policy Memo December 8, 2011 Federal Cloud Computing Strategy February 8, 2011 Creating Effective Cloud Computing Contracts February 24, 2012 Slide 9

Cloud: 25 Point Plan to Reform IT Cloud First Policy Point 3 of the White House s 25 Point Plan to Reform Federal IT Requires agencies to evaluate safe, secure cloud options before making any new investments. This means agencies should evaluate their technology sourcing plans to include cloud solutions as part of the budget process. Three Cloud Projects by June 9, 2012 Cloud First mandates agencies move three projects to the cloud At least 1 project had to move to the cloud by December 9, 2011; 2 additional must move by June 9, 2012. Slide 10

Cloud Computing Strategy Overview Details benefits of cloud to Federal government Provides decision framework for moving to the cloud Case examples to illustrate framework Promotes vision for catalyzing cloud adoption across Federal government Slide 11

Cloud Security: FedRAMP Federal Risk and Authorization Management Program Overview Mandatory for Federal agencies via OMB Policy Memo Creates government wide security process for cloud computing solutions Provides assessments, provisional authorizations, and continuous monitoring of cloud services Transparent processes for Federal agencies and cloud service providers Establishes a Federal government standard baseline for securing cloud environments Slide 12

Cloud Procurement White Paper Overview Top 10 areas Federal agencies need to address when procuring cloud Gives description of issues along with ways to address issues within contracts Provides tactical guidance through a questionnaire checklist Slide 13

Partnership of IT, Acquisition, Legal Today, the CIO Council, CAO Council, and Federal Cloud Compliance Committee released: Creating Effective Cloud Computing Contracts for the Federal Government: Best Practices for Acquiring IT as a Service. This guide enables Federal agencies to make smarter, more informed cloud purchasing decisions by utilizing lessons learned and best practices of early adopters moving us to a more efficient and more effective government. Steven VanRoekel U.S. Chief Information Officer, OMB February 24, 2012 Slide 14

Development of White Paper Two Tier Approach to Creating Guidance. Existing Cloud Contracts Develop lessons learned from early adopters Informal data call through OMB to collect ~15 existing Federal cloud contracts Review of contracts to see variance of contract terms, establish baseline and identify themes Interview project managers and contracting officers of each contract: What worked What doesn t work How various issues were addressed FC3 Guidance Guidance Developed by Federal Cloud Compliance Committee (FC3) Informal interagency group comprised of Federal Attorneys, procurements officials, and cloud SMEs. Mission: create tactical guidance to proactively assist agencies when contracting cloud Created four working groups: Security Privacy E Discovery Records Management/FOIA Slide 15

Goals of White Paper Cloud Computing and the Federal Government: Effectively Acquiring IT as a Service Merge the Cloud First mandate and the visionary Cloud Computing Strategy The next step in government s move to cloud with specific guidance in effectively buying cloud services Provide guidance to agencies in developing requirements for a cloud computing contract. Highlight top ten areas for Federal agencies to address in cloud contracts Help shape the way that cloud computing services are purchased and consumed Establish common practices for the Federal government to take advantage of its position as the largest purchaser of IT Slide 16

Top 10 Focus Areas 1) Selecting a Cloud Service 2) CSP and End User Agreements 3) Service Level Agreements (SLAs) 4) CSP, Agency, and Integrator Roles and Responsibilities 5) Standards 6) Security 7) Privacy 8) E Discovery 9) Freedom of Information Act (FOIA) 10) E Records Slide 17

Selecting a Cloud, End User Agreements ONE Selecting a Cloud Service Agencies must choose the appropriate cloud to meet their needs Determine the appropriate service model to meet user needs Determine the appropriate deployment model that meets data protection needs TWO CSP & End User Agreements Terms of Service Agreements (TOS) need to be negotiated TOS must be compliant with Federal laws and statutes Need to ensure NDA enforceability End User Agreements need to be integrated fully into cloud contracts Slide 18

SLAs and CSP, Agency, Integrator Rs & Rs THREE Service Level Agreements SLAs should clearly define CSP performance standards Need clear terms and definitions Need to determine how CSP performance will be measured Needs to establish enforcement mechanisms for SLA compliance FOUR CSP, Agency, & Integrator Roles and Responsibilities Establishes a contract with (at least) three parties Determine integrator role with CSP Need to clearly define the roles and responsibilities of all actors to ensure effectiveness of the cloud contract Slide 19

Standards and Security FIVE Standards Agencies should ensure CSPs align with government standards Map services to NIST Reference Architecture Ensure government participation in standards creation Compliance with Internet Protocol version 6 SIX Security FedRAMP Compliance Clearly defined requirements Continuous monitoring activities Incident response to attacks and vulnerabilities Key escrow/encryption Forensic capabilities Multi factor authentication with HSPD 12 Audit capabilities Slide 20

Privacy and E Discovery SEVEN Privacy Ensure compliance with the Privacy Act of 1974 and PII requirements Privacy Impact Assessments Adequate privacy training Clearly defined data location requirements How to respond to a breach where privacy data was compromised EIGHT E Discovery Provide information management in the cloud Ability to locate relevant documents Ability to preserve data in a cloud environment Moving documents through the e discovery process Cost avoidance by inclusion of tools with CSP solution Slide 21

FOIA and Federal Recordkeeping NINE FOIA Access Ability to conduct a reasonable search to meet Freedom of Information Act (FOIA) obligations Ensure the processing of information is pursuant to FOIA requirements Allow for the tracking and reporting of information pursuant to FOIA TEN Federal Recordkeeping Agencies should have proactive records planning before using a cloud service Ensure the ability to have timely and actual destruction of records in accordance with mandated records schedules How to deal with permanent records Process for transitioning to a new CSP Slide 22

Appendix A: Questionnaire Overview Translates the paper to tactical questions to ask when reviewing or creating a cloud contract Maps to the ten areas of focus within the paper Tactical approach for Agencies to use Slide 23

White Paper: Key Takeaway All necessary stakeholders should be included when creating cloud computing contracts. OCIO OGC Privacy Records E Discovery FOIA Acquisition staff This will enable Federal agencies to more effectively procure and manage IT as a service Slide 24

Cloud Resources CIO Council www.cio.gov Federal Cloud Computing Initiative www.info.apps.gov FedRAMP www.fedramp.gov NIST http://www.nist.gov/itl/cloud NARA http://www.archives.gov/records mgmt/bulletins/2010/2010 05.html Slide 25

Questions? Matt Goodrich Federal Cloud Computing Initiative, GSA Cloud Computing Best Practices matt.goodrich@gsa.gov Allison Stanton Director, E Discovery, DOJ Civil Division allison.stanton@usdoj.gov