Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence

Subscribe to Updates

Get the latest National Security News directly to your inbox.

What's Hot

Щоб перемогти тиранію, потрібне більше єднання; демократичний світ здатен його досягти – звернення Володимира Зеленського

March 30, 2023

Serebrian: Trebuie consolidat rolul UE în procesul de reglementare

March 30, 2023

Serebrian speră că Misiunea OSCE în Moldova își va continua activitatea

March 30, 2023
Facebook Twitter Instagram
  • Privacy Policy
  • Terms and Conditions
  • Contact
Thursday, March 30
Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence
en English
en Englishet Estonianlv Latvianlt Lithuanianpl Polishro Romanianru Russianuk Ukrainian
Trending
  • Щоб перемогти тиранію, потрібне більше єднання; демократичний світ здатен його досягти – звернення Володимира Зеленського
  • Serebrian: Trebuie consolidat rolul UE în procesul de reglementare
  • Serebrian speră că Misiunea OSCE în Moldova își va continua activitatea
  • Usatîi: Eu cu Dodon și Năstase nu mă filmez nici în film
  • Un partid solicită inițierea unui Pact pentru Justiție
  • Maia Sandu, după întrevederea cu Charles Michel: Contăm pe sprijinul UE
  • Ajutor pentru Guvern din partea României. Va fi creat un nou departament
  • Letonia este un susținător puternic al parcursului european al Moldovei
Subscribe
Facebook Twitter Instagram
Estonian Free PressEstonian Free Press
Home » OIG Reports on DoD Use of Commercial Cloud Services

OIG Reports on DoD Use of Commercial Cloud Services

February 18, 20233 Mins Read Cybersecurity
Share
Facebook Twitter LinkedIn Pinterest Email

The Office of Inspector General (OIG) at the Department of Defense (DoD) has completed an assessment as to whether DoD Components complied with Federal and DoD security requirements when using commercial cloud services.

Since 2011, the DoD has acquired commercial cloud services to meet mission needs. Commercial cloud services allow users to store, access, and share data and software using the Internet rather than locally storing information on servers or computer hard drives. DoD Component authorizing officials (AOs) are responsible for granting the system‑level authorization to operate (ATO) when using authorized commercial cloud service offerings (CSOs).

OIG found that the Army, Navy, Air Force, and Marine Corps used three commercial CSOs that were Federal Risk and Authorization Management Program (FedRAMP) and DoD authorized and at the appropriate DoD impact level for the five systems reviewed. However, OIG found that the AOs did not review all required documentation to consider the commercial CSOs’ risks to their systems when granting and reassessing ATOs on a periodic basis thereafter. Specifically, the AOs did not consider system risks that were identified in the supporting documentation of the authorized commercial CSOs’ FedRAMP and DoD authorization processes and continuous monitoring activities.

OIG said this occurred because all five AOs believed that the FedRAMP and DoD authorization processes were sufficient to mitigate risk to their respective systems. OIG believes that unless AOs review all required documentation to consider the risks to their respective systems, DoD Components may be unaware of vulnerabilities and cybersecurity risks associated with operating their systems or storing their data in the authorized commercial CSOs.

The watchdog recommends that the Chief Information Officers (CIO) for the Army, Air Force, and Department of the Navy require the AOs to reevaluate the ATOs for the five cloud systems OIG reviewed. OIG also recommend that the DoD CIO emphasize the importance of following the DoD Cloud Computing Security Requirements Guide (SRG) when using commercial CSOs. In addition, OIG recommend that the Defense Information Systems Agency (DISA) Director coordinate with the Joint Authorization Board for FedRAMP to require that commercial cloud service providers remediate all vulnerabilities or provide documentation that describes why the risk to mission impact is low. 

In response, the Army and Department of the Navy CIOs agreed to reevaluate the ATOs for the systems reviewed to ensure compliance with the DoD Cloud Computing SRG. The Air Force Deputy CIO agreed that the Air Force would review and update guidance but did not address whether the AOs would reevaluate the ATOs. 

The DoD CIO agreed to emphasize the importance of complying with the DoD Cloud Computing SRG and the DISA CIO agreed to continued collaboration with the FedRAMP Joint Authorization Board to ensure cloud service providers remediate vulnerabilities or document risk acceptance.

Read the full report at DoD OIG

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Articles Liés

[email protected]: Patricia Cogswell, Former Deputy Administrator of TSA, Reflects on Twenty Years

March 29, 2023 Cybersecurity

Malicious links still on EU Commission website as hackers change tactics

March 29, 2023 Cybersecurity

IRS Building on ‘Exemplary’ Capabilities to Deflect Surge of Cyber Attack Attempts

March 28, 2023 Cybersecurity

The Dark Side of ChatGPT and Other Large Language Models

March 28, 2023 Cybersecurity

Biden Signs Executive Order to Prohibit U.S. Government Use of Commercial Spyware that Poses Risks to National Security

March 27, 2023 Cybersecurity

Cybersecurity focus in second Digital Europe work programme

March 27, 2023 Cybersecurity
Don't Miss
Moldova

Serebrian: Trebuie consolidat rolul UE în procesul de reglementare

By woe whMarch 30, 20230

Viceprim-ministrul pentru Reintegrare, Oleg Serebrian, consideră că este necesară consolidarea rolului Uniunii Europene în procesul…

Serebrian speră că Misiunea OSCE în Moldova își va continua activitatea

March 30, 2023

Usatîi: Eu cu Dodon și Năstase nu mă filmez nici în film

March 30, 2023

Un partid solicită inițierea unui Pact pentru Justiție

March 30, 2023
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

Ajutor pentru Guvern din partea României. Va fi creat un nou departament

March 30, 2023

Letonia este un susținător puternic al parcursului european al Moldovei

March 29, 2023

Cabinetul de miniștri s-a întrunit într-o nouă ședință

March 29, 2023

CUB: Pornim numărătoarea inversă pentru guvernare în domeniul energetic

March 29, 2023

Subscribe to Updates

Get the latest National Security News directly to your inbox.

© 2023 Estonian Free Press. All rights reserved.
  • Privacy Policy
  • Terms and Conditions
  • Contact

Type above and press Enter to search. Press Esc to cancel.