FedRAMP Briefing. Matt Goodrich, JD FedRAMP Director, GSA

Similar documents
Highlights of DoD Industry Information Day on the DFARS Cyber Rule

Career Pathway. The term "career pathway'' means a combination of rigorous and high-quality education, training and other services that

DoD Cloud Computing Strategy Needs Implementation Plan and Detailed Waiver Process

EXECUTIVE OFFICE OF THE PRESIDENT OFFICE OF MANAGEMENT AND BUDGET WASHINGTON, D.C February 27, 2018

Together. Free your energies. Cheuvreux Autumn Conference. September 29, Paul Hermelin, CEO

Better results through sourcing. Andrew Hewat LODESTAR Advisory Services

Success through Offshore Outsourcing. Kartik Jayaraman Director Enterprise Relationships (Strategic Accounts)

Company Overview. Copyright 2014 Accenture All rights reserved. 1

What s New? for. DoG Logo. Thursday, May 4th at 6pm - Friday, May 5th at 6pm

MISSION INNOVATION ACTION PLAN

Prepared Statement. Vice Admiral Raquel Bono, M.D. Director, Defense Health Agency REGARDING ELECTRONIC HEALTH RECORD MANAGEMENT BEFORE THE

UNLOCKING BUSINESS VALUE OUTSOURCING DEALS FROM SECOND GENERATION

Background and progress

Report No. D July 30, Data Migration Strategy and Information Assurance for the Business Enterprise Information Services

Aligning Business & Technology: Driving Positive Change Across the Commonwealth

The Premier Source for CIO and Executive Technology Talent

Rules and Procedures Overview. Kickstart:Wyoming Program SBIR Phase I and II Matching Program

Generating Business Value from Information Technology

A New Approach for Delivering Information Technology Capabilities in the Department of Defense

Medicaid and Human Services Transparency and Fraud Prevention Act Progress Report

Quality Assurance (QA) Work Plan. Advance Corrections Initiative

Effectiveness of the Department of Defense Information Assurance Accreditation Process

Lance J. Kerwin. Career Snapshot

Defense Travel Management Office

MEDIA RELEASE POLYTECHNICS PARTNER WITH MAS AND INDUSTRY PLAYERS TO LAUNCH THE FIRST POLYFINTECH 100 API HACKATHON

Azores. Application Form Information. Application Form Information Azores. portugalventures.pt

Government IT. Strategies. Irma Mentzer Information Management Technology World Bank Group

An agile approach to outsourcing

From DIACAP to RMF A Clear Path to a New Framework

February 2 nd, 2017 #SIMCLT. Taking IT Up A Notch! SIM Charlotte Region. 1st Quarter Event

Department of Defense INSTRUCTION

Approach for the Erie St. Clair Local Health Integration Network (ESC LHIN) Primary Health Care Task Group

CENTRAL LHIN CEO REPORT CORRESPONDENCE

DEFENSE LOGISTICS AGENCY THE NATION S COMBAT LOGISTICS SUPPORT AGENCY

The World s Most Important Gathering of CIOs and Senior IT Executives

Request for Proposals

Program Results Examples

DoDI ,Operation of the Defense Acquisition System Change 1 & 2

GEF-7 Policy Agenda. First Meeting for the 7 th Replenishment Paris, France March 30, 2017

Patient Safety Reporting System for Nursing Homes Patient Safety Authority Commonwealth of Pennsylvania. Government to Business (G to B)

DEFENSE TRAVEL MANAGEMENT OFFICE. Defense Travel Management Office FY 2017 FY 2021 Strategic Plan

The Army Executes New Network Modernization Strategy

Using Technology to Solve California s Agriculture and Natural Resource Challenges

HEALTHBOX Studio Report

BMO Harris Bank Community Impact Review Spring 2018

Coupons.com Accelerates Company Growth with

Empowering the Third Sector in Self-renewal Process: Building up Collaborative and Innovative Problem Solving Platform in Hong Kong

SUBJECT: Army Directive (Implementation of the Army Human Capital Big Data Strategy)

The Stimulus Plan. Our Perspective. Al Gordon Chief Executive Officer, NSI.

Audit Report. Global Fund Grant Making Processes Follow-up Review. GF-OIG May 2017 Geneva, Switzerland

Army Identity and Access Management (IdAM)

OBELICS PRELIMINARY CALL FOR EXPRESSIONS OF INTEREST. Giovanni Lamanna, LAPP. Document V1 14/12/2016

Name Position Telephone First contact

Inspector General. Summary of Internal Control Issues Over the. Peace Corps. Financial Reporting. Office of. Background FISCAL YEAR 2017

UNCLASSIFIED. R-1 ITEM NOMENCLATURE PE F: Joint Command and Control. FY 2011 Total Estimate. FY 2011 OCO Estimate

Power Projection: - Where We Were - Where We Are - Where We Need To Be

Structuring the content of large-scale Electronic Patient Records

ITC: DEDICATED TO THE SUCCESS OF BUSINESSES THROUGH TRADE

Drinking Water Operator Certification and Certificate to Operate Criteria/Requirements for US Navy Overseas Drinking Water Systems

GSI Health. Powering the future of Healthcare HEALTHCARE SPECIAL. The Navigator for Enterprise Solutions IN MY OPINION CIOREVIEW.COM FEBRUARY 14, 2017

Internal Audit Co-sourcing

2003 NASCIO Recognition Awards State of Tennessee Digital Government: Government to Citizen (G to C)

Forecast to Industry 2016

F O R G R E AT E R H E A LT H

Strategic Vision. Rapidly Delivering Cyber Warfighting Capability From Seabed to Space. Space and Naval Warfare Systems Command

Next Generation United Networks for Higher Education and Healthcare Service Oriented Architecture

Department of Defense Fiscal Year (FY) 2016 IT President's Budget Request Overview

Visualizing the Patient Experience Using an Agile Framework

Models for Innovation

The Wave 2 MU-MIMO Wi-Fi Opportunity for Channel Partners

40 PM NETWORK JANUARY 2015

FY2025 Master Plan/ FY Strategic Plan Summary

Approved by WQGIT July 14, 2014

IMDRF FINAL DOCUMENT. Title: Strategic Assessment of Electronic Submission Messaging Formats

Services to Local Government

City of Painesville, Ohio

Tuesday - February 14th, 2017

Department of Defense Investment Review Board and Investment Management Process for Defense Business Systems

Department ofthe Navy Business Transformation Plan Fiscal Year 2013 & Fiscal Year 2012 Annual Report

COMMUNITY PROJECT PROPOSAL

U.S. Air Force. AF Cyber Resiliency Office for Weapon Systems (CROWS) I n t e g r i t y - S e r v i c e - E x c e l l e n c e

Deputy Director, C5 Integration

Take These Actions to Immediately Improve Patient Throughput

The Army s Mission Command Battle Lab

Next Steps to Revolutionary Change of Spectrum Usage

Efficiency 1717 H Street, NW, Suite 825 Washington, DC Fax: (202)

FY16 Enterprise Mobility Suite (EMS) Adoption Offer Frequently Asked Questions

Inteligentní pracovní prostředí

Department of Defense Fiscal Year (FY) 2015 IT President's Budget Request Overview

UNCLASSIFIED. LandWarNet Army Request for IT (ARFIT) Information Exchange Forum (IEF)

Transitioning to ICD-10. Presented by: The Centers for Medicare & Medicaid Services

The ideal Local Authority. Green Deal and ECO

COMMONWEALTH OF PENNSYLVANIA GOVERNOR'S OFFICE. Payments to Local Governments and Other Subrecipients

Roadmap to accountable care: The chicken or the egg technology investment or clinical process improvement?

xcel-hcahps: A New Approach for Improving Patient Satisfaction

New Models for Community Engagement in Real Estate

Exhibit R-2, RDT&E Budget Item Justification

THE JOINT STAFF Research, Development, Test and Evaluation (RDT&E), Defense-Wide Fiscal Year (FY) 2009 Budget Estimates

MSM Research Grant Program 2018 Competition Guidelines

Business Plan: Corporate Investments & Partnerships

Transcription:

FedRAMP Briefing Matt Goodrich, JD FedRAMP Director, GSA Date August 2017

FedRAMP: LATEST STATS The program has been in existence for 5 years, formally launching in June 2012 5 YEARS We have DOUBLED the number of cloud providers and authorizations each year since launch We currently have 86 33% authorized Cloud Service Providers 33% of those that are authorized are small business Since inception, agencies have re-used authorizations 505 times That means every authorization has been reused approximately 6x 110 110 155 44 161 45 PAGE 2

FedRAMP ACCELERATED & FedRAMP READY FedRAMP Accelerated demonstrated the PMO s ability to reduce JAB authorization timelines by over 75%. Transformed the ATO Process to Take Less Than 6 Months Reduced Timelines from 18-24 months down to approximately 4 months on average Still maintained the same level of rigor in reviews as previous process Increased security reviews by incorporating Continuous Monitoring into process Key Element of Success was FedRAMP Ready Many CSPs begin unaware of what gaps exist within their system This results in unforeseen costs and time for CSPs in the authorization process The FedRAMP Readiness Assessment Report helps identify a CSP s security implementations upfront in the process - for gov t to understand success likelihood, and a CSP to use as a self assessment PAGE 3

FedRAMP CONNECT: OVERVIEW The JAB will be selecting 12 vendors per year to work with for a FedRAMP JAB Provisional ATO (P-ATO) FedRAMP Connect - Evolving the Selection Process To help evolve the program, the PMO worked with the JAB, OMB and the CIO Council to develop clear, transparent criteria to prioritize CSPs for working with the JAB toward a P-ATO Based on current resources and funding, the JAB has the capacity to authorize up to 12 CSPs a year Selection Criteria Demand is now the number one criterion for prioritization; it is also the only requirement for prioritization There are also a range of preferential criteria if demand is all considered equal (Govt cloud vs commercial, High impact vs Moderate impact, etc.) Selection Process We received roughly 40 business cases for the inaugural FedRAMP Connect, held in early 2017 We selected 14 vendors to pitch their services to the JAB and 13 agency CIOs and their representatives The JAB prioritized 7 vendors and have kicked-off the authorization process Even if a vendor wasn t selected for the JAB, we are working closely with the vendors to identify an agency match - 6 vendors have been matched to date. Upcoming Milestones We are now accepting business case applications for the next round of FedRAMP Connect until 25 August, 5pm. Applications are due by 5pm on 25 August 2017, with the target date of the next FedRAMP Connect set for October 2017 PAGE 4

FedRAMP TAILORED: OVERVIEW Not all SaaS are Created Equal FedRAMP was originally built around enterprise-wide solutions that would cover the broadest range of data types for cloud architectures and low, moderate, and high impact FedRAMP tailored addresses low risk use SaaS focusing on things like collaboration, project management, and open-source code development You would not secure your 2017 Cadillac Escalade the same way you would secure your Huffy Bike. You need a more rigorous security mechanism for the SUV, while a U-lock device will suffice to secure your bicycle. PAGE 5

FedRAMP TAILORED: BENEFITS Benefits of FedRAMP Tailored: Balance: New baseline will provide agencies with agility to leverage valuable services while maintaining the appropriate level of security. Simplicity: The SSP, SAP, SAR, and Remediation Plans are combined into a single document (defined control-by-control). Separate attachments for the risk summary table and Plan of Action & Milestones (POA&M) are used for initial ATO and ConMon. Speed: This process can be completed in as little as 4 weeks. Economical: The simplified ATO documentation means Agencies and SaaS providers save time, effort, and costs. Secure: The security is commensurate with the risk (total of 36 controls). PAGE 6

Questions? PAGE 7