- Unauthorized application use: 70% of IT professionals believe the use of unauthorized programs resulted in as many as half of their companies' data loss incidents.
- Misuse of corporate computers: 44% of employees share work devices with others without supervision.
- Unauthorized physical and network access: 39% of IT professionals said they have dealt with an employee accessing unauthorized parts of a company's network or facility.
- Remote worker security: 46% of employees admitted to transferring files between work and personal computers when working from home.
- Misuse of passwords: 18% of employees share passwords with co-workers. That rate jumps to 25 percent in China, India, and Italy.
Tuesday, April 5, 2016
Plugging Data Leaks
Tuesday, February 10, 2015
The Internet of Me, Myself & I
What happens when the gadgets you wear also control the things around you?
No doubt you've heard of various internet-connected things like light bulbs, coffee makers and thermostats making their way into our homes. And no doubt, you've probably heard of such devices that you wear (or insert) to track your fitness, sleeping or even blood sugar levels. But when that sleeping monitor can alert the light bulb and coffee machine that you are about to wake up, that's called the Internet of Self. Data from your body that is used to control the objects around you. Your body controls the your environment, without you even knowing.
Cool and for me, a bit unnerving at the same time.
![]() |
| Image Courtesy Fortifyprotect.com |
A ComputerWorld article talks about all the amazing ways this is going to change our lives. For example, there is sleep monitoring technology that can alert a light bulb to turn on gradually as if it is a sunrise, based on your own sleep patterns. Forget those eye squints when the calm darkness suddenly disappears with the flip of a switch. The light is now taking commands from your body. Automakers are installing technology that monitors your face & eyes and if you start doing the doze-dip with your head, it'll alert you to pull over or even pull you over itself. Even your home security cameras can take a look at your face, compare it to a database, and unlock your garage and doors. The unlocking of the door tells the kitchen or any other room to turn on the lights. Your biometric data is controlling the things around you. Clothing will have stress meters, cars with breathalyzers, belts that auto extend after a big meal. You get the picture.
Congress also has some concerns. Reps. Darrell Issa, (R-CA)., and Suzan DelBene, (D-WA) have formed a new Congressional Caucus on the Internet of Things to educate members about the issue. This is to educate members so they can make more informed policy decisions about this technology. The big issue is protecting consumer's privacy as more sensitive personal information is being sent and received by a growing number of these things. Hacked data and the prying eyes of the government and other entities are tops on their list.
The FCC has asked that they hold off on any legislation tied directly to IoT since it is evolving so fast but did recommend that a data breach bill requiring 30 day consumer notification of a breach be passed. People have already been infiltrated through their thermostats and there was news yesterday that certain smart-TV's will capture and send your private conversations - if picked up by the voice recognition - to a third party data processor. Add to that, robots are already attacking within the home. Forget zombies, vacuums are the real threat.
The ComputerWorld article make this IoSelf seem so easy with just an app and a device - it's just 'easy to create software.' Not exactly. While some apps, I'm sure, are easy to create, there is much more than just an app and device going on...like an actual application in a data center for the app &/or device to communicate with and the proper security protections for such transactions. The article seems to gloss over any cautions and there is no mention of privacy, security or any of the potential risks involved with the Internet of Self. Do I really want my various biometrics stored in some third-party cloud somewhere just so I can unlock my front door with a wink? Probably not.
For now, I'm happy to pull out my physical keys, hand turn the knob and use my index finger to disable the alarm. I know it is I who did it, not some reasonable facsimile thereof.
ps
Related
- Here comes the 'Internet of Self'
- Congress sees security risk in 'Internet of Things'
- 70% Of Internet-Connected Appliances Are Vulnerable To Hacking
- How hackers could slam on your car's brakes
- Cybersecurity in the Age of Intelligent Energy: Putting the Nest Thermostat ‘Hack’ in Context
- Top 5 Smart Home Devices We Expect To Emerge In 2015
- A robot vacuum tried to eat its sleeping owner's head
| Connect with Peter: | Connect with F5: |
| |
Tuesday, May 28, 2013
FedRAMP Federates Further
FedRAMP (Federal Risk and Authorization Management Program), the government’s cloud security assessment plan, announced late last week that Amazon Web Services (AWS) is the first agency-approved cloud service provider. The accreditation covers all AWS data centers in the United States. Amazon becomes the third vendor to meet the security requirements detailed by FedRAMP. FedRAMP is the result of the US Government’s work to address security concerns related to the growing practice of cloud computing and establishes a standardized approach to security assessment, authorizations and continuous monitoring for cloud services and products. By creating industry-wide security standards and focusing more on risk management, as opposed to strict compliance with reporting metrics, officials expect to improve data security as well as simplify the processes agencies use to purchase cloud services. FedRAMP is looking toward full operational capability later this year.
As both the cloud and the government’s use of cloud services grow, officials found that there were many inconsistencies to requirements and approaches as each agency began to adopt the cloud. Launched in 2012, FedRAMP’s goal is to bring consistency to the process but also give cloud vendors a standard way of providing services to the government. And with the government’s cloud-first policy, which requires agencies to consider moving applications to the cloud as a first option for new IT projects, this should streamline the process of deploying to the cloud. This is an ‘approve once, and use many’ approach, reducing the cost and time required to conduct redundant, individual agency security assessment. AWS's certification is for 3 years.
FedRAMP provides an overall checklist for handling risks associated with Web services that would have a limited, or serious impact on government operations if disrupted. Cloud providers must implement these security controls to be authorized to provide cloud services to federal agencies. The government will forbid federal agencies from using a cloud service provider unless the vendor can prove that a FedRAMP-accredited third-party organization has verified and validated the security controls. Once approved, the cloud vendor would not need to be ‘re-evaluated’ by every government entity that might be interested in their solution. There may be instances where additional controls are added by agencies to address specific needs.
The BIG-IP Virtual Edition for AWS includes options for traffic management, global server load balancing, application firewall, web application acceleration, and other advanced application delivery functions.
ps
Related:
- Cloud Security With FedRAMP
- FedRAMP Ramps Up
- FedRAMP achieves another cloud security milestone
- Amazon wins key cloud security clearance from government
- Cloud Security With FedRAMP
- CLOUD SECURITY ACCREDITATION PROGRAM TAKES FLIGHT
- FedRAMP comes fraught with challenges
- F5 iApp template for NIST Special Publication 800-53
- Now Playing on Amazon AWS - BIG-IP
- Connecting Clouds as Easy as 1-2-3
- F5 Gives Enterprises Superior Application Control with BIG-IP Solutions for Amazon Web Services
| Connect with Peter: | Connect with F5: |
| |
Wednesday, August 15, 2012
Parking Ticket Privacy
Imagine getting a $20 parking ticket and then filing suit against the issuing municipality for exposing too much personal information on that ticket. That’s exactly what Jason Senne did after receiving a $20 parking ticket in 2010 for illegally parking his car overnight in the Chicago ‘burb of Palatine, Ill. His name, address, driver's license number, date of birth, height and weight all appeared on the ticket, which was placed on his windshield in full public view. Senne's complaint alleged that disclosure of his identity was in violation of the Driver’s Privacy Protection Act of 1994 (DPPA). DPPA requires that all states protect a driver's name, address, phone number, Social Security number, driver identification number, photograph, height, weight, gender, age, and specific medical or disability information. Congress passed the privacy legislation in response to the death of actress Rebecca Schaeffer. She was killed by a stalker who had gotten her unlisted home address through the California DMV. In Senne’s case, initially a federal judge found that an exception for law enforcement protected the village's actions, and a 3-judge panel of the 7th Circuit affirmed that last year. Senne pushed and the full federal appeals court agreed to rehear the case. Last week, the full federal appeals court decided Monday that ‘the parking ticket at issue here did constitute a disclosure regulated by the DPPA.’
In a 7-4 ruling, the appeals court said that it didn’t matter if someone walking by happened to notice the personal info – just the fact that it was exposed in such a public manner was enough. The earlier district court decision, in favor of Palatine Village, was based on the notion that a ‘disclosure’ was when an entity turned over information to someone else without consent and was not considered disclosure. In this case, there was no direct handoff, just the ticket flapping on the windshield/wiper blade in plain sight. In the overturned ruling, the divided court felt that there was real risk, safety and security concerns at stake. A stalker looking for a target could just hang out where overnight parking is banned and collect a bunch of potential victim’s info for future harassment. The recent court’s interpretation of the law might also expose Palatine to a hefty $80 million fine. Since there is a 4 year statute of limitations on private lawsuits and each privacy violation carries a $2500 penalty, all those tickets issued during that time frame with the protected info could be in play.
It’s an interesting case about privacy and how others, without malicious intent, may expose personal, sensitive details about an individual. While identity theft due to electronic means, like data breaches, is on the rise, stolen wallets or physical documents (dumpster diving) still account for a good percentage of ID theft crimes. Back in 2009, a Javelin study indicated that stolen wallets and physical documents accounts for 43% of all identity theft (pdf) which means we still need to shred our printed materials.
ps
References:
- Privacy Issue in Parking Tickets, Full Circuit Says
- Appeals court reinstitutes parking ticket lawsuit against Palatine
- Detailed Parking Tickets Breach Personal Privacy, Appeals Court Says
- Court Says Parking Tickets Could Be Illegal
- Senne v. Village of Palatine
- Driver Information Can Be Sold for Commercial Use Under DPPA (FindLaw's Seventh Circuit Blog)
- Driver's Privacy Protection Act Seems Fairly Useless (FindLaw's Sixth Circuit Blog)
- Dumpster Diving vs. The Bit Bucket
Technorati Tags: F5, smartphone, integration, byod, Pete Silva, security, business, education, technology, application delivery,ipad,mobile device, context-aware,android, iPhone, web, internet, security
| Connect with Peter: | Connect with F5: |
| |
Tuesday, June 5, 2012
FedRAMP Ramps Up
Tomorrow June 6th, the Federal Risk and Authorization Management Program, the government’s cloud security assessment plan known as FedRAMP will begin accepting security certification applications from companies that provide software services and data storage through the cloud. On Monday, GSA issued a solicitation for cloud providers, both commercial and government, to apply for FedRAMP certification. FedRAMP is the result of government’s work address security concerns related to the growing practice of cloud computing and establishes a standardized approach to security assessment, authorizations and continuous monitoring for cloud services and products. By creating industry-wide security standards and focusing more on risk management, as opposed to strict compliance with reporting metrics, officials expect to improve data security as well as simplify the processes agencies use to purchase cloud services, according to Katie Lewin, director of the federal cloud computing program at the General Services Administration.
As both the cloud and the government’s use of cloud services grew, officials found that there were many inconsistencies to requirements and approaches as each agency began to adopt the cloud. FedRAMP’s goal is to bring consistency to the process but also give cloud vendors a standard way of providing services to the government. And with the government’s cloud-first policy, which requires agencies to consider moving applications to the cloud as a first option for new IT projects, this should streamline the process of deploying to the cloud. This is an ‘approve once, and use many’ approach, reducing the cost and time required to conduct redundant, individual agency security assessment.
Recently, the GSA released a list of nine accredited third-party assessment organizations—or 3PAOs—that will do the initial assessments and test the controls of providers per FedRAMP requirements. The 3PAOs will have an ongoing part in ensuring providers meet requirements.
FedRAMP provides an overall checklist for handling risks associated with Web services that would have a limited, or serious impact on government operations if disrupted. Cloud providers must implement these security controls to be authorized to provide cloud services to federal agencies. The government will forbid federal agencies from using a cloud service provider unless the vendor can prove that a FedRAMP-accredited third-party organization has verified and validated the security controls. Once approved, the cloud vendor would not need to be ‘re-evaluated’ by every government entity that might be interested in their solution. There may be instances where additional controls are added by agencies to address specific needs.
Independent, third-party auditors are tasked with testing each product/solution for compliance which is intended to save agencies from doing their own risk management assessment. Details of the auditing process are expected early next month but includes a System Security Plan that clarifies how the requirements of each security control will be met within a cloud computing environment. Within the plan, each control must detail the solutions being deployed such as devices, documents and processes; the responsibilities of providers and government customer to implement the plan; the timing of implementation; and how solution satisfies controls. A Security Assessment Plan details how each control implementation will be assessed and tested to ensure it meets the requirements and the Security Assessment Report explains the issues, findings, and recommendations from the security control assessments detailed in the security assessment plan. Ultimately, each provider must establish means of preventing unauthorized users from hacking the cloud service.
The regulations allow the contractor to determine which elements of the cloud must be backed up and how frequently. Three backups are required, one available online. All government information stored on a provider's servers must be encrypted. When the data is in transit, providers must use a "hardened or alarmed carrier protective distribution system," which detects intrusions, if not using encryption. Since cloud services may span many geographic areas with various people in the mix, providers must develop measures to guard their operations against supply chain threats. Also, vendors must disclose all the services they outsource and obtain the board's approval to contract out services in the future.
After receiving the initial applications, FedRAMP program officials will develop a queue order in which to review authorization packages. Officials will prioritize secure Infrastructure as a Service (IaaS) solutions, contract vehicles for commodity services, and shared services that align with the administration’s Cloud First policy.
F5 has an iApp template for NIST Special Publication 800-53 which aims to make compliance with NIST Special Publication 800-53 easier for administrators of BIG-IPs. It does this by presenting a simplified list of configuration elements together in one place that are related to the security controls defined by the standard. This makes it easier for an administrator to configure a BIG-IP in a manner that complies with the organization's policies and procedures as defined by the standard. This iApp does not take any actions to make applications being serviced through a BIG-IP compliant with NIST Special Publication 800-53 but focuses on the configuration of the management capabilities of BIG-IP and not on the traffic passing through it.
ps
Resources:
- Cloud Security With FedRAMP
- CLOUD SECURITY ACCREDITATION PROGRAM TAKES FLIGHT
- FedRAMP comes fraught with challenges
- FedRAMP about to hit the streets
- FedRAMP takes applications for service providers
- Contractors dealt blanket cloud security specs
- FedRAMP includes 168 security controls
- New FedRAMP standards first step to secure cloud computing
- GSA to tighten oversight of conflict-of-interest rules for FedRAMP
- What does finalized FedRAMP plan mean for industry?
- New FedRAMP standards first step to secure cloud computing
- GSA reopens cloud email RFQ
- NIST, GSA setting up cloud validation process
- FedRAMP Security Controls Unveiled
- FedRAMP security requirements benchmark IT reform
- FedRAMP baseline controls released
- Federal officials launch FedRAMP
Technorati Tags: F5, federal government, integration, cloud computing, Pete Silva, security, business, fedramp, technology, nist, cloud, compliance, regulations, web,internet
| Connect with Peter: | Connect with F5: |
| |
Wednesday, April 25, 2012
Complying with PCI DSS–Part 6: Maintain an Information Security Policy
According to the PCI SSC, there are 12 PCI DSS requirements that satisfy a variety of security goals. Areas of focus include building and maintaining a secure network, protecting stored cardholder data, maintaining a vulnerability management program, implementing strong access control measures, regularly monitoring and testing networks, and maintaining information security policies. The essential framework of the PCI DSS encompasses assessment, remediation, and reporting. We’re exploring how F5 can help organizations gain or maintain compliance and the last entry is Maintain an Information Security Policy which includes PCI Requirement 12. To read Part 1, click: Complying with PCI DSS–Part 1: Build and Maintain a Secure Network, Part 2:Complying with PCI DSS–Part 2: Protect Cardholder Data, Part 3: Complying with PCI DSS–Part 3: Maintain a Vulnerability Management Program, Part 4: Complying with PCI DSS–Part 4: Implement Strong Access Control Measures and Part 5: Complying with PCI DSS–Part 5: Regularly Monitor and Test Networks.
Requirement 12: Maintain a policy that addresses information security for all personnel.
PCI DDS Quick Reference Guide description: A strong security policy sets the security tone for an entire organization’, and it informs employees of their expected duties related to security. All employees should be aware of the sensitivity of cardholder data and their responsibilities for protecting it.
Solution: The spirit of this requirement is to ensure the adoption of a Corporate Information Security Policy (CISP). Although policy-based, F5 solutions don’t, by themselves, meet this requirement in context. F5 products facilitate adherence to the CISP, but they do not actually comprise a CISP. That said, F5 products can help organizations roll out business policies and security policies together. Applications needn’t be built and deployed in a vacuum; F5 technologies can be implemented in conjunction with corporate policies that address information security.
Since the inception of the PCI DSS, organizations have been laboring to understand, implement, and comply with its guidelines. Often, achieving that goal requires deploying and managing several different types of devices. The BIG-IP platform enables organizations to understand inherent threats and take specific measures to protect their web application infrastructures and to satisfy many PCI DSS requirements.
ps
Related:
- Complying with PCI DSS–Part 1: Build and Maintain a Secure Network
- Complying with PCI DSS–Part 2: Protect Cardholder Data
- Complying with PCI DSS–Part 3: Maintain a Vulnerability Management Program
- Complying with PCI DSS–Part 4: Implement Strong Access Control Measures
- Complying with PCI DSS–Part 5: Regularly Monitor and Test Networks
- PCI Turns 2.0
- Will you Comply or just Check the Box?
- Cloud Balancing, Reverse Cloud Bursting, and Staying PCI-Compliant
- BIG-IP v10.1 Application Security Manager PCI Reporting
- Visa Kills PCI Assessments And Wants Your Processor To Support EMV
- Complying with PCI DSS
Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet,cybercrime, holiday shopping, identity theft,
| Connect with Peter: | Connect with F5: |
| |
Tuesday, April 17, 2012
Complying with PCI DSS–Part 1: Build and Maintain a Secure Network
According to the PCI SSC, there are 12 PCI DSS requirements that satisfy a variety of security goals. Areas of focus include building and maintaining a secure network, protecting stored cardholder data, maintaining a vulnerability management program, implementing strong access control measures, regularly monitoring and testing networks, and maintaining information security policies. The essential framework of the PCI DSS encompasses assessment, remediation, and reporting. Over the next several blogs, we’ll explore how F5 can help organizations gain or maintain compliance. Today is Build and Maintain a Secure Network which includes PCI Requirements 1 and 2.
PCI DSS Quick Reference Guide, October 2010
The PCI DSS requirements apply to all “system components,” which are defined as any network component, server, or application included in, or connected to, the cardholder data environment. Network components include, but are not limited to, firewalls, switches, routers, wireless access points, network appliances, and other security appliances. Servers include, but are not limited to, web, database, authentication, DNS, mail, proxy, and NTP servers. Applications include all purchased and custom applications, including internal and external web applications. The cardholder data environment is a combination of all the system components that come together to store and provide access to sensitive user financial information. F5 can help with all of the core PCI DSS areas and 10 of its 12 requirements.
Requirement 1: Install and maintain a firewall and router configuration to protect cardholder data.
PCI DSS Quick Reference Guide description: Firewalls are devices that control computer traffic allowed into and out of an organization’s network, and into sensitive areas within its internal network. Firewall functionality may also appear in other system components. Routers are hardware or software that connects two or more networks. All such devices are in scope for assessment of Requirement 1 if used within the cardholder data environment. All systems must be protected from unauthorized access from the Internet, whether via e-commerce, employees’ remote desktop browsers, or employee email access. Often, seemingly insignificant paths to and from the Internet can provide
unprotected pathways into key systems. Firewalls are a key protection mechanism for any computer network.
Solution: F5 BIG-IP products provide strategic points of control within the Application Delivery Network (ADN) to enable truly secure networking across all systems and network and application protocols. The BIG-IP platform provides a unified view of layers 3 through 7 for both general reporting and alerts and those required by ICSA Labs, as well as for integration with products from security information and event management (SIEM) vendors. BIG-IP Local Traffic Manager (LTM) offers native, high-performance firewall services to protect the entire infrastructure. BIG-IP LTM is a purpose-built, high-performance Application Delivery Controller (ADC) designed to protect Internet data centers. In many instances, BIG-IP LTM can replace an existing firewall while also offering scalability, performance, and persistence. Running on an F5 VIPRION chassis, BIG-IP LTM can manage up to 48 million concurrent connections and 72 Gbps of throughput with various timeout behaviors and buffer sizes when under attack. It protects UDP, TCP, SIP, DNS, HTTP, SSL, and other network attack targets while delivering uninterrupted service for legitimate connections. The BIG-IP platform, which offers a unique Layer 2–7 security architecture and full packet inspection, is an ICSA Labs Certified Network Firewall.
Replacing stateful firewall services with BIG-IP LTM in the data center architecture
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters.
PCI DSS Quick Reference Guide description: The easiest way for a hacker to access your internal network is to try default passwords or exploits based on the default system software settings in your payment card infrastructure. Far too often, merchants do not change default passwords or settings upon deployment. This is akin to leaving your store physically unlocked when you go home for the night. Default passwords and settings for most network devices are widely known. This information, combined with hacker tools that show what devices are on your network, can make unauthorized entry a simple task if you have failed to change the defaults.
Solution: All F5 products allow full access for administrators to change all forms of access and service authentication credentials, including administrator passwords, application service passwords, and system monitoring passwords (such as SNMP). Products such as BIG-IP Access Policy Manager (APM) and BIG-IP Edge Gateway limit remote connectivity to only a GUI and can enforce two-factor authentication, allowing tighter control over authenticated entry points. The BIG-IP platform allows the administrator to open up specific access points to be fitted into an existing secure network. BIG-IP APM and BIG-IP Edge Gateway offer secure, role-based administration (SSL/TLS and SSH protocols) and virtualization for designated access rights on a per-user or per-group basis. Secure Vault, a hardware-secured encrypted storage system introduced in BIG-IP
version 9.4.5, protects critical data using a hardware-based key that does not reside on the appliance’s file system. In BIG-IP v11, companies have the option of securing their cryptographic keys in hardware, such as a FIPS card, rather than encrypted on the BIG-IP hard drive. The Secure Vault feature can also encrypt certificate passwords for enhanced certificate and key protection in environments where FIPS 140-2 hardware support is not required, but additional physical and role-based protection is preferred. Secure Vault encryption may also be desirable when deploying the virtual editions of BIG-IP products, which do not support key encryption on hardware.
Next: Protect Cardholder Data
ps
Related:
- PCI Turns 2.0
-
Cloud Balancing, Reverse Cloud Bursting, and Staying PCI-Compliant
-
Visa Kills PCI Assessments And Wants Your Processor To Support EMV
Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet,cybercrime, holiday shopping, identity theft,
| Connect with Peter: | Connect with F5: |
| |
Tuesday, January 10, 2012
Cloud Security With FedRAMP
Want to provide Cloud services to the federal government? Then you’ll have to adhere to almost 170 security controls under the recently announced Federal Risk and Authorization Management Program. The program, set to go live in June, is designed to analyze/audit cloud computing providers for federal government agencies, expedite security clearances for cloud providers and foster the adoption of cloud computing by the Federal government. FedRAMP is meant to provide a baseline for low to moderate risk systems and is based on the NIST cyber-security Special Publication 800-53 Revision 3. FedRAMP provides an overall checklist for handling risks associated with Web services that would have a limited, or serious impact on government operations if disrupted. Cloud providers must implement these security controls to be authorized to provide cloud services to federal agencies. The government will forbid federal agencies from using a cloud service provider unless the vendor can prove that a FedRAMP-accredited third-party organization has verified and validated the security controls. Once approved, the cloud vendor would not need to be ‘re-evaluated’ by every government entity that might be interested in their solution. There may be instances where additional controls are added by agencies to address specific needs.
Independent, third-party auditors are tasked with testing each product/solution for compliance which is intended to save agencies from doing their own risk management assessment. Details of the auditing process are expected early next month but includes a System Security Plan that clarifies how the requirements of each security control will be met within a cloud computing environment. Within the plan, each control must detail the solutions being deployed such as devices, documents and processes; the responsibilities of providers and government customer to implement the plan; the timing of implementation; and how solution satisfies controls. A Security Assessment Plan details how each control implementation will be assessed and tested to ensure it meets the requirements and the Security Assessment Report explains the issues, findings, and recommendations from the security control assessments detailed in the security assessment plan. Ultimately, each provider must establish means of preventing unauthorized users from hacking the cloud service.
The regulations allow the contractor to determine which elements of the cloud must be backed up and how frequently. Three backups are required, one available online. All government information stored on a provider's servers must be encrypted. When the data is in transit, providers must use a "hardened or alarmed carrier protective distribution system," which detects intrusions, if not using encryption. Since cloud services may span many geographic areas with various people in the mix, providers must develop measures to guard their operations against supply chain threats. Also, vendors must disclose all the services they outsource and obtain the board's approval to contract out services in the future.
More details of the FedRAMP program will be available from the General Services Administration by February 8th, but they have already started accepting applications for third party assessment vendors.
ps
Resources:
- Contractors dealt blanket cloud security specs
- FedRAMP includes 168 security controls
- New FedRAMP standards first step to secure cloud computing
- GSA to tighten oversight of conflict-of-interest rules for FedRAMP
- What does finalized FedRAMP plan mean for industry?
- New FedRAMP standards first step to secure cloud computing
- GSA reopens cloud email RFQ
- NIST, GSA setting up cloud validation process
- FedRAMP Security Controls Unveiled
- FedRAMP security requirements benchmark IT reform
- FedRAMP baseline controls released
- Federal officials launch FedRAMP
- Audio: Steven VanRoekel announces FedRAMP
- NIST: Cloud providers should adopt portability standards
- Cloud security breach inevitable as businesses underestimate security due diligence
Technorati Tags: F5, federal government, integration, cloud computing, Pete Silva, security, business, fedramp, technology, nist, cloud, compliance, regulations, web, internet
| Connect with Peter: | Connect with F5: |
| |


