7 ms·
Oracle was already on the FedRAMP list I think. AFAIK this is about getting smaller cloud providers approved to host government projects so there’s more options
by tcfunk 1y ago
Oracle was already on the FedRAMP list I think. AFAIK this is about getting smaller cloud providers approved to host government projects so there’s more options available.
- ritwikgupta 1y agoThis is about changing the way FedRAMP accreditation is done for any cloud service, like Box (or a new SaaS that you may create tomorrow). The FedRAMP process requires you go through a certain set of audits, meet a certain set of standards, etc., in order to be approved to host CUI (IL4/5) or SECRET (IL6) information. Normally this can take a lot of time and monetary investment. On one hand, these processes encode cybersecurity best practices. On another hand, it keeps new companies out of the market. It seems this effort is doing away with a lot of those processes. I hope the level of compliance stays the same.
- ksec 1y agoBut why would any agency chooses smaller cloud providers other than Oracle, AWS, Azure and Google? They are the lowest risk selection in terms of responsibility. Edit: Another comments actually replied it is much more than hosting but cloud services like BOX. I assume even SaaS could fall into this category.
- tguvot 1y agoSaas is most common use case
- cyberge99 1y agoTo stay off the radar. To do shady stuff at a small company that you can easily control/manipulate.
- Spooky23 1y agoThey tend to converge on each other. Also the Feds may have particular needs for connectivity, location, etc.
- justincormack 1y agoSaaS companies, not just cloud providers.